data:image/s3,"s3://crabby-images/62ba8/62ba86b6e7cf0ff0e867bb9a06f07118cb967475" alt="H3C S9500E Series Скачать руководство пользователя страница 17"
17
Figure 3
Basic message exchange process of RADIUS
RADIUS operates in the following way:
1.
The host initiates a connection request carrying the username and password to the RADIUS
client.
2.
Having received the username and password, the RADIUS client sends an authentication
request (Access-Request) to the RADIUS server, with the user password encrypted by using
the Message-Digest 5 (MD5) algorithm and the shared key.
3.
The RADIUS server authenticates the username and password. If the authentication succeeds,
it sends back an Access-Accept message containing the user’s authorization information. If
the authentication fails, it returns an Access-Reject message.
4.
The RADIUS client permits or denies the user according to the returned authentication result.
If it permits the user, it sends a start-accounting request (Accounting-Request) to the RADIUS
server.
5.
The RADIUS server returns a start-accounting response (Accounting-Response) and starts
accounting.
6.
The user accesses the network resources.
7.
The host requests the RADIUS client to tear down the connection and the RADIUS client
sends a stop-accounting request (Accounting-Request) to the RADIUS server.
8.
The RADIUS server returns a stop-accounting response (Accounting-Response) and stops
accounting for the user.
9.
The user stops access to network resources.
RADIUS packet format
RADIUS uses UDP to transmit messages. UPD ensures a smooth message exchange between the
RADIUS server and the client through a series of mechanisms, including the timer management