294
Basic RADIUS message exchange process
illustrates the interactions between the host, the RADIUS client, and the RADIUS server.
Figure 312 Basic RADIUS message exchange process
RADIUS operates in the following manner:
1.
The host initiates a connection request that carries the user's username and password to the
RADIUS client.
2.
Having received the username and password, the RADIUS client sends an authentication
request (Access-Request) to the RADIUS server, with the user password encrypted using the
MD5 algorithm and the shared key.
3.
The RADIUS server authenticates the username and password. If the authentication succeeds,
the server returns an Access-Accept message containing the user's authorization information.
If the authentication fails, the server returns an Access-Reject message.
4.
The RADIUS client permits or denies the user according to the returned authentication result. If
it permits the user, it sends a start-accounting request (Accounting-Request) to the RADIUS
server.
5.
The RADIUS server returns an acknowledgement (Accounting-Response) and starts
accounting.
6.
The user accesses the network resources.
7.
The host requests the RADIUS client to tear down the connection and the RADIUS client sends
a stop-accounting request (Accounting-Request) to the RADIUS server.
8.
The RADIUS server returns an acknowledgement (Accounting-Response) and stops
accounting for the user.
RADIUS packet format
RADIUS uses UDP to transmit messages. To ensure smooth message exchange between the
RADIUS server and the client, RADIUS uses a timer management mechanism, a retransmission
mechanism, and a backup server mechanism.
shows the RADIUS packet format.
Содержание FlexNetwork NJ5000
Страница 12: ...x Index 440 ...
Страница 39: ...27 Figure 16 Configuration complete ...
Страница 67: ...55 Figure 47 Displaying the speed settings of ports ...
Страница 78: ...66 Figure 59 Loopback test result ...
Страница 158: ...146 Figure 156 Creating a static MAC address entry ...
Страница 183: ...171 Figure 171 Configuring MSTP globally on Switch D ...
Страница 243: ...231 Figure 237 IPv6 active route table ...
Страница 293: ...281 Figure 298 Ping operation summary ...