E-5
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Appendix E Cisco Secure ACS and Virtual Private Dial-up Networks
VPDN Process
Figure E-7
NAS Authenticates Tunnel with ACS
7.
After authenticating, the tunnel is established. Now the actual user
([email protected]) must be authenticated. See
Figure E-8
.
Figure E-8
VPDN Tunnel is Established
8.
The HG now authenticates the user as if the user dialed directly in to the HG.
The HG might now challenge the user for a password. The Cisco Secure ACS
at RSP can be configured to strip off the @ and domain before it passes the
authentication to the HG. (The user is passed as [email protected].) The
HG uses its ACS to authenticate the user. See
Figure E-9
.
S6651
Username = home_gate
Password = CHAP_stuff
Corporation
VPDN user
User = [email protected]
ACS
RSP
ACS
CHAP response
S6652
Corporation
VPDN user
User = [email protected]
ACS
RSP
ACS