Configuring Global Settings
2-21
Setting Authentication for Dial-In Users
Setting Authentication for Dial-In Users
You can configure the PortMaster for three authentication methods, PAP, CHAP, and
username/password login.
By default, PAP and CHAP are set to on. Dial-in users are asked to authenticate with
PAP when PPP is detected. If users refuse, they are asked to authenticate with CHAP.
If you set PAP to off, and CHAP to on, dial-in users are asked to authenticate with
CHAP. PAP authentication is neither requested nor accepted. If you set both PAP and
CHAP to off, dial-in users must authenticate with a username/password login.
To set PAP authentication, use the following command:
Command> set pap on|off
To set CHAP authentication, use the following command:
Command> set chap on|off
Setting Call-Check Authentication
You can enable services without authenticating the user at the point of entry on
PortMaster products that support PRI or in-band signaling. Use the show global
command to find out if call-check is enabled on your PortMaster.
To enable the call-check feature in ComOS, you must first configure call-check user
entries on the RADIUS 2.1 server. Otherwise, the PortMaster issues a busy signal to
every call. See the RADIUS for UNIX Administrator’s Guide for more information about
RADIUS.
To enable call checking on the PortMaster, use the following command:
Command> set call-check on|off
Note – The call-check feature is off by default.
If the call-check feature is on, the PortMaster sends a ringing message to the switch
while the service information is being looked up in RADIUS.
RADIUS does one of the following:
•
Rejects the message with a busy signal
•
Acknowledges the call and allows the call to be completed with no special service
type determined during the call
•
Allows the creation of a netdata clear channel TCP or L2TP connection to the
destination specified in the RADIUS user profile
Call-check enables the PortMaster—via RADIUS—to check the telephone number of a
caller before answering the call. The PortMaster can then hang up and call the user back
with no charge incurred for connecting the user in the first place. Alternatively, the
PortMaster can reject the call to limit the number of users who can call a given number,
such as an 800 number, or to prevent certain users from calling the number.
✍
Содержание PortMaster 4
Страница 12: ...Contents xii PortMaster Configuration Guide...
Страница 24: ...Basic Configuration Steps 1 6 PortMaster 4 Configuration Guide...
Страница 48: ...PortMaster Security Management 2 24 PortMaster 4 Configuration Guide...
Страница 102: ...Testing Your Location Configuration 7 12 PortMaster 4 Configuration Guide...
Страница 122: ...Configuring Ports for Modem Use 9 8 PortMaster 4 Configuration Guide...
Страница 152: ...Performing Diagnostics 11 4 PortMaster 4 Configuration Guide...
Страница 162: ...Frame Relay Subinterfaces 12 10 PortMaster 4 Configuration Guide...
Страница 168: ...Troubleshooting a Leased Line Connection 13 6 PortMaster 4 Configuration Guide...
Страница 182: ...Command Index Command Index 4 PortMaster 4 Configuration Guide...