1.
Create an AAA profile that supports preauthentication (by using the
pre-authenticate
command in AAA Profile Configuration mode).
2.
Specify the IP address of a RADIUS preauthentication server (by using the
radius
pre-authentication server
command in Global Configuration mode) and of an
authentication server (by using the
radius authentication server
command in
Global Configuration mode).
The following steps describe how the router uses RADIUS to obtain and use the LLID.
It is assumed that you have already configured an AAA profile for preauthentication
and have defined both a RADIUS preauthentication server and a RADIUS
authentication server. Typically, the preauthentication server and the authentication
server reside in the same virtual router context in which the PPP subscriber is
authenticated.
The router obtains and uses the LLID as follows:
1.
A PPP subscriber requests authentication through RADIUS.
2.
The router sends an Access-Request message to the RADIUS preauthentication
server to obtain an LLID for the subscriber.
This step is referred to as the preauthentication request because it occurs before
user authentication and authorization.
3.
The preauthentication server returns the LLID to the router in the Calling-Station-Id
(RADIUS attribute 31) of an Access-Accept message.
The router ignores any RADIUS attributes other than the Calling-Station-Id that
are returned in the preauthentication Access-Accept message.
4.
The router encodes the LLID in the RADIUS Calling-Station-Id and sends an
Access-Request message to the RADIUS authentication server.
This step is referred to as the authentication request.
5.
The RADIUS authentication server returns an Access-Accept message to the
router that includes the tunnel attributes for the subscriber session.
6.
For tunneled PPP subscribers, the router, acting as an L2TP access concentrator
(LAC), encodes the LLID into L2TP Calling Number AVP 22 and sends this to the
L2TP network server (LNS) in an incoming-call request (ICRQ) packet.
After a successful preauthentication request, the router always encodes the LLID
in Calling Number AVP 22. The use of
aaa
commands such as
aaa tunnel
calling-number-format
to control or change the inclusion of the LLID in Calling
Number AVP 22 has no effect.
RADIUS Attributes in Preauthentication Request
Table 5 on page 78 describes the RADIUS IETF attributes that are always included
in a preauthentication request to obtain the LLID. The attributes are listed in ascending
order by standard number.
Using the AAA Logical Line Identifier to Track Subscribers
■
77
Chapter 1: Configuring Remote Access
Содержание JUNOSE 11.0.X MULTICAST ROUTING
Страница 6: ...vi...
Страница 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 274: ...234 CLI Commands Used to Modify RADIUS Attributes JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 408: ...368 Configuring the Weighted Load Balancing Method JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 492: ...452 Monitoring Operational Status within the Current VR Context JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 528: ...488 Configuring the Router to Work with the SRC Software JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 632: ...592 Subscriber Management Configuration Examples JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 636: ...596 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 672: ...632 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 767: ...Part 7 Index Index on page 729 Index 727...
Страница 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...