Avaya G250 and G250-BRI Branch Office Media Gateways w/FIPS Non-Proprietary Security Policy
Version 1.2 Wednesday, 14 December, 2005
© 2005 Avaya Inc.
May be reproduced only in its original entirety [without revision]. Page 12 of 23
CID 106595
User) authentication
database.
configuration and status indications.
Read Only
User
Identity-based
operator
authentication
Username and Password. The module
stores user identity information in an
internal or an external Radius Server
database.
An assistant to the Admin User that
has read only access to a subset of
module configuration and status
indications.
Radius Client
Role-based
operator
authentication
Shared Radius secret.
Gateway authenticates Radius server
response by examining the MD5 hash
of the shared secret, the request
Authenticator, and other response
values in a response message.
An entity authenticates to the module
for the purpose of permitting/denying
access to services.
OSPF Router
Peer
Role-based
operator
authentication
Router peer Secret
Authentication of OSPF protocol
executed by examining the
authentication field in OSPF packet
carrying MD5 hash of the packet and
the secret.
An entity authenticates to the module
for the purpose of permitting/denying
access to services.
PPPoE client
Role-based
operator
authentication
Chap/Pap Secrets
Simple password authentication is
used for PAP-based authentication.
Gateway use MD5 function to hash
the challenge and the secret value in
the response message to PPPoE
Server.
An entity that facilitates connection
to the broadband access network
using PPP over Ethernet protocol.
PPPoE client can be attached only to
WAN Ethernet port.
IKE Peer
Role-based
operator
authentication
IKE pre-shared keys.
An entity that facilitates IPSec VPNs.
Serial Number
Peer
Role based
authentication
TDES encrypted challenge.
Gateway exchanges its serial number
with a Server to enable feature
activation.
Table 5 - Roles and Required Identification and Authentication
4.2.
Strengths of Authentication Mechanisms
All passwords used for role or identity authentication are accepting 94 ASCII codes. The
authentication strength is shown in
Table 6
below.
Role
Minimum
password
length
Probability of successfully
authenticating
Probability of successfully
authenticating in one minute
OSPF, PPPoE,
Radius
6 characters
1/ 689,869,781,056
1 / 209,052
Crypto Officer,
User, Read-Only
User
8 characters
1 / 6,095,689,385,410,816
1 / 1,847,178,602