125
state. It only receives and processes the synchronization messages and does not process
packets from the server.
Portal authentication across VPNs
In a scenario where the branches belong to different VPNs that are isolated from each other and all
portal users in the branches must be authenticated by the server at the headquarters, deploy portal
authentication across MPLS VPNs. As shown in
, the PE connecting the authentication clients
serves as the NAS. The NAS is configured with portal authentication and AAA authentication, both of
which support authentication across VPNs. Therefore, the NAS can transparently transmit a client's
portal authentication packets in a VPN through the MPLS backbone to the servers in another VPN. This
implements centralized authentication of clients in different VPNs while ensuring the separation of
packets of the different VPNs.
Figure 50
Network diagram for portal authentication across VPNs
NOTE:
•
Portal authentication configured on MCE devices can also support authentication across VPNs. For
information about MCE, see
MPLS Configuration Guide .
•
For information about AAA implementation across VPNs, see "
•
This feature does not apply to VPNs with overlapping address spaces.