
Dial VPN Layer 3 Tunneling
303509-A Rev 00 3-13
If the TMS finds a match in its database for both the user and domain names,
it determines that this user is a Dial VPN user and a candidate for tunnel
creation. The TMS then checks that the number of current connections does
not exceed the maximum number of users allowed.
If the TMS determines that the user is not a tunnel candidate, the NAS first
treats the request as a proxy RADIUS request and attempts to authenticate this
user in the usual way. See the description of proxy RADIUS in the BSAC
Administration Guide for your platform.
4.
If the dial-in request is a tunnel candidate, the NAS starts the
authentication process and builds a tunnel.
Once it determines that this request is a tunnel candidate, the TMS tells the
NAS to contact the gateway for remote authentication. For a given domain,
authentication and address allocation can take place locally, using ACP (in an
erpcd-based network), or remotely, using RADIUS and DHCP on the
customer’s network. If the request is not a tunnel candidate, the NAS uses
local (instead of remote) authentication.
The NAS receives the remote node’s address, the source of which depends on
the type of authentication and the type of IP address allocation.
5.
The RADIUS client on the gateway sends a request to the RADIUS server
on the home network to authenticate the remote user.
During remote authentication, the RADIUS authentication server on the home
network verifies that the remote node is authorized to access the home
network and determines which network services the remote node is allowed to
use.
6.
The DHCP server or the RADIUS server on the home network assigns an
IP address and includes that address in the reply to the gateway.
Note:
The system administrator can change the default requirements for the
Dial VPN user name format as needed.
Note:
The TMS may deny a tunnel request for a number of reasons; for
example, if the maximum number of users has been reached, if the TMS does
not find a match for the domain name in its database, or if the authentication
request fails. If the tunnel request is denied, the connection between the NAS
and the remote node is dropped.
Commentaires sur ces manuels