Mapping User Requests Without a Configured Domain Name
You can map a domain name called
none
to a specific virtual router so that the router
can map user names that do not contain a domain name.
If a user request is submitted without a domain name, the router looks for a mapping
between the domain name
none
and a virtual router. If a match is found, the user’s
request is processed according to the RADIUS server configured for the named virtual
router. If the router does not find the domain name
none
, it checks for the domain
name
default
. If no matching entries are found, the router sends the request to the
server configured on the default virtual router.
Using DNIS
The E Series router supports dialed number identification service (DNIS). With DNIS,
if users have a called number associated with them, the router searches the domain
map for the called number. If it finds a match, the router uses the matching domain
map entry information to authenticate the user. If the router does not find a match,
it searches the domain map using normal processing.
NOTE:
For DNIS to work, the router must be acting as the LNS. Also, the phone
number configured in the
aaa domain-map
command must be an exact match to
the value passed by L2TP in the called number AVP (AVP 21).
For example, as specified in the following sequence, a user calling 9785551212
would be terminated in vrouter_88, while a user calling 8005554433 is terminated
in vrouter_100.
host1(config)#
aaa domain-map 9785551212 vrouter_88
host1(config)#
aaa domain-map 8005554433 vrouter_100
Redirected Authentication
Redirected authentication provides a way to offload AAA activity on the router, by
providing the domain-mapping-like feature remotely on the RADIUS server. Redirected
authentication works as follows:
1.
The router sends an authentication request (in the form of a RADIUS
access-request message) to the RADIUS server that is configured in the default
VR.
2.
The RADIUS server determines the user’s AAA VR context and returns this
information in a RADIUS response message to the router.
3.
The router then behaves in similar fashion as if it had received the VR context
from the local domain map.
To maintain local control, the only VR allowed to redirect authentication is the default
VR. Also, to prevent loopbacks, the redirection may occur only once to a non-default
VR.
Mapping a User Domain Name to a Virtual Router
■
9
Chapter 1: Configuring Remote Access
Содержание JUNOSE 11.0.X MULTICAST ROUTING
Страница 6: ...vi...
Страница 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 274: ...234 CLI Commands Used to Modify RADIUS Attributes JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 408: ...368 Configuring the Weighted Load Balancing Method JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 492: ...452 Monitoring Operational Status within the Current VR Context JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 528: ...488 Configuring the Router to Work with the SRC Software JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 632: ...592 Subscriber Management Configuration Examples JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 636: ...596 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 672: ...632 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 767: ...Part 7 Index Index on page 729 Index 727...
Страница 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...