Setting the ISDN Switch
2-22
PortMaster 4 Configuration Guide
You can also use call-check to support virtual points of presence (POPs) by redirecting a
call. If a caller dials one number, the PortMaster can authenticate normally. If a caller
dials a different number, the PortMaster can accept the call and forward the caller
information through a netdata (TCP clear) or L2TP connection to an IP address and port
of your choosing, where another process handles the user.
Additionally, you can provide guest access or establish tunnels based on dial number
information services. Call checking can be done against the calling number ID (CNID) or
calling line ID (CLID) or both. The RADIUS attributes are Called-Station-Id and
Calling-Station-Id, respectively.
Setting the ISDN Switch
You can configure the switch provisioning for ISDN PRI connections to PortMaster ISDN
ports. See Chapter 10, “Configuring T1, E1, and ISDN PRI,” for details on PRI
connections.
PortMaster Security Management
The PortMaster provides security through the user table, or if configured, RADIUS
security. When a dial-in user attempts to authenticate at the login prompt, or via PAP or
CHAP authentication, the PortMaster refers to the entry in the user table that
corresponds to the user. If the password entered by the user does not match, the
PortMaster denies access with an “Invalid Login” message. If no user table entry exists
for the user and port security is off, the PortMaster passes the user on to the host
defined for that port using the selected login service. In this situation, the specified host
is expected to authenticate the user.
If port security is on and the user was not found in the user table, the PortMaster
queries the RADIUS server, if one has been configured. If the username is not found in
the user table, port security is on, and no RADIUS server is configured in the global
configuration of the PortMaster, access is denied with an “Invalid Login” message. If the
RADIUS server is queried and does not respond within 30 seconds (and neither does the
alternate RADIUS server), access is denied with an “Invalid Login” message.
If security is off, any username that is not found in the user table is sent to the port’s
host for authentication and login. If security is on, the user table is checked first. If the
username is not found and a RADIUS server is configured, RADIUS is consulted. When
you are using RADIUS security, you must use the set C0 security command to set
security to on.
Access can also be denied if the specified login service is unavailable—for example, if the
PortMaster Login Service has been selected for the user but the selected host does not
have the in.pmd PortMaster daemon installed. Access is denied with the “Host Is
Currently Unavailable” message if the host is down or otherwise not responding to the
login request.
Содержание PortMaster 4
Страница 12: ...Contents xii PortMaster Configuration Guide...
Страница 24: ...Basic Configuration Steps 1 6 PortMaster 4 Configuration Guide...
Страница 48: ...PortMaster Security Management 2 24 PortMaster 4 Configuration Guide...
Страница 102: ...Testing Your Location Configuration 7 12 PortMaster 4 Configuration Guide...
Страница 122: ...Configuring Ports for Modem Use 9 8 PortMaster 4 Configuration Guide...
Страница 152: ...Performing Diagnostics 11 4 PortMaster 4 Configuration Guide...
Страница 162: ...Frame Relay Subinterfaces 12 10 PortMaster 4 Configuration Guide...
Страница 168: ...Troubleshooting a Leased Line Connection 13 6 PortMaster 4 Configuration Guide...
Страница 182: ...Command Index Command Index 4 PortMaster 4 Configuration Guide...