You can also use an optional RADIUS proxy server to provide additional enhancements
to the 802.1x-based environment. For example, the RADIUS proxy server enables
subscribers to be multiplexed to multiple Internet service providers (ISPs) that are
customers of the same carrier. The server performs one of the following actions:
■
If the ISP’s RADIUS server supports EAP, the RADIUS proxy server extends the
EAP session to the RADIUS server.
■
If the ISP’s RADIUS server does not support EAP, the RADIUS proxy server
translates the EAP session into a legacy RADIUS session for the RADIUS server.
Authentication and Addressing
The WAP initiates the authentication and authorization request by sending a standard
RADIUS Access-Request to the RADIUS relay server. The Access-Request must include
the attributes listed in Table 47 on page 247. The attributes uniquely identify the
wireless subscriber.
Table 47: Required RADIUS Access-Request Attributes
Description
Attribute Name
Subscriber’s WAP
Called-Station-id [30]
Subscriber’s media access control (MAC) address
Calling-Station-id [31]
When the RADIUS server authenticates the subscriber, the router’s RADIUS relay
server creates a RADIUS Access-Accept message and sends the message back to the
subscriber. The router’s DHCP server (either the router’s DHCP local server or an
external DHCP server) assigns an IP address to the subscriber and creates the
subscriber interface.
For information about using the optional SRC software with the RADIUS relay server
to assign IP addresses, see “RADIUS Relay Server and the SRC Software” on page 248.
The WAP might periodically reauthenticate a subscriber. For example, reauthentication
is necessary to renegotiate a new Wired Equivalent Privacy (WEP) key. The RADIUS
relay server ignores any new RADIUS attributes that are sent during a renegotiation
operation.
Accounting
The RADIUS relay server’s clients (the WAPs) send standard accounting request
messages to the RADIUS relay server. The accounting server processes the request
and sends the results back to the RADIUS relay server, which then creates a RADIUS
accounting response message and forwards the information to the client WAP.
For tracking purposes, the forwarding RADIUS relay server adds the
Radius-Client-Address vendor-specific attribute (VSA 26-52) to the forwarded
accounting request messages. The VSA indicates the RADIUS relay server’s IP address.
How RADIUS Relay Server Works
■
247
Chapter 5: Configuring RADIUS Relay Server
Содержание JUNOSE 11.0.X MULTICAST ROUTING
Страница 6: ...vi...
Страница 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 274: ...234 CLI Commands Used to Modify RADIUS Attributes JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 408: ...368 Configuring the Weighted Load Balancing Method JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 492: ...452 Monitoring Operational Status within the Current VR Context JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 528: ...488 Configuring the Router to Work with the SRC Software JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 632: ...592 Subscriber Management Configuration Examples JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 636: ...596 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 672: ...632 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 767: ...Part 7 Index Index on page 729 Index 727...
Страница 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...