7.5.1 RADIUS
RADIUS (Remote Authentication Dial In User Service) is a service that enables authentica-
tion and configuration information to be exchanged between your device and a RADIUS
server. The RADIUS server administrates a database with information about user authen-
tication and configuration and for statistical recording of connection data.
RADIUS can be used for:
• Authentication
• Accounting
• Exchange of configuration data
For an incoming connection, your device sends a request with user name and password to
the RADIUS server, which then searches its database. If the user is found and can be au-
thenticated, the RADIUS server sends corresponding confirmation to your device. This con-
firmation also contains parameters (called RADIUS attributes), which your device uses as
WAN connection parameters.
If the RADIUS server is used for accounting, your device sends an accounting message at
the start of the connection and a message at the end of the connection. These start and
end messages also contain statistical information about the connection (IP address, user
name, throughput, costs).
RADIUS packets
The following types of packets are sent between the RADIUS server and your device
(client):
Packet types
Field
Value
ACCESS_REQUEST
Client -> Server
If an access request is received by your device, a request is
sent to the RADIUS server if no corresponding connection part-
ner has been found on your device.
ACCESS_ACCEPT
Server -> Client
If the RADIUS server has authenticated the information con-
tained in the ACCESS_REQUEST, it sends an AC-
CESS_ACCEPT to your device together with the parameters
used for setting up the connection.
7 System Management
bintec elmeg GmbH
108
bintec RS Series