governed by nonconfigurable values for retransmission attempts and interval. The
configuration of the RADIUS client determines retransmission values for response
packets to the RADIUS server. The retransmission values are as follows:
■
PPP makes five attempts to retransmit an EAP request before the authentication
attempt is terminated. You cannot configure the number of retransmission
attempts.
■
When an EAP request is transmitted, a timer is started with a nonconfigurable
retransmission interval value of 3 seconds. When the timer expires, the EAP
request is retransmitted.
In some cases, you might want a longer retransmission interval. For example, you
might need to accommodate the additional time required by a user to enter
information or scan a fingerprint or retina. RADIUS can instruct the JUNOSe software
to wait longer by passing an appropriate Session-Timeout attribute in the RADIUS
Access-Challenge packet. This retransmission interval value applies only to the EAP
request packet present in the RADIUS Access-Challenge packet.
The Session-Timeout attribute value overrides the default retransmission interval
value, up to a maximum of 30 seconds. If RADIUS recommends a greater value, then
PPP resets it back to 30 seconds in order to avoid longer or infinite delays.
EAP Behavior in an L2TP Environment
EAP behavior in an L2TP environment varies depending on whether the router acts
as a LAC or an LNS,
When the E Series Router Acts as a LAC
When PPP forwards an EAP identity response packet to AAA, AAA might be configured
to return a tunnel response upon successful validation of the packet. You can use
AAA domain maps, a AAA profile, or both to force such tunneling.
On an LAC, PPP forwards the PPP EAP authentication information to the LNS during
the establishment of the L2TP session. This authentication information consists of
the EAP type, the data appropriate to the type (such as a username) contained in the
EAP identity response packet, and the identifier of the EAP identity response packet.
If the LNS trusts the LAC, then the LNS uses this authentication information to resume
the EAP negotiation where the LAC left off.
L2TP on an LAC forwards the PPP EAP authentication information in the Proxy
Authen AVPs as described in L2TP Proxy Authenticate Extensions for
EAP—draft-ietf-l2tpext-proxy-authen-ext-eap-01.txt (December 2006 expiration).
When the E Series Router Acts as an LNS
PPP on an LNS resumes the EAP negotiation operation by detecting the presence of
EAP information in the proxy authentication data supplied by L2TP. PPP reconstructs
the EAP identity response packet from the proxy authentication data and forwards
it to AAA.
Overview
■
269
Chapter 8: Configuring Point-to-Point Protocol
Содержание JUNOSE 11.1.X - LINK LAYER CONFIGURATION 4-7-2010
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 26: ...xxvi List of Figures JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 34: ...2 Chapters JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 200: ...168 Monitoring Upper Level Protocols over Ethernet JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 230: ...198 Monitoring VLAN and S VLAN Subinterfaces JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 258: ...226 Monitoring 802 3ad Link Aggregation JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 334: ...302 Troubleshooting JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 394: ...362 Monitoring Multiclass MLPPP JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 406: ...374 Monitoring POS JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 468: ...436 Troubleshooting JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 498: ...466 Monitoring Bridged Ethernet JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 546: ...514 Monitoring Cisco HDLC JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 747: ...Part 2 Index Index on page 717 Index 715...
Страница 748: ...716 Index JUNOSe 11 1 x Link Layer Configuration Guide...
Страница 774: ...742 Index JUNOSe 11 1 x Link Layer Configuration Guide...