
A-2 RADIUS Authentication Process
LX Series Configuration Guide
RADIUS Authentication Process
The following example describes the steps in the RADIUS
authentication process. In this example, the user attempts to
gain access to an LX asynchronous port.
1. The LX unit prompts the user for a username and password.
2. The LX unit takes the username and password and creates
an access-request packet identifying the LX unit making the
request, the username and password, and the port being
used. The LX unit then sends the access-request packet to
the designated RADIUS server for authentication.
L The user password is encrypted to prevent it from
being intercepted and reused by an unwanted user.
This is done by generating a random vector and
placing it in the request header. A copy of the
random vector is MD5 encoded using the configured
secret. The user’s password is then encrypted by
XORing it with the encoded copy of the random
vector.
3. The RADIUS server validates the request and then decrypts
the password.
4. The username and password are authenticated by the
RADIUS server.
5. Upon successful authentication, the RADIUS server sends an
access-accept packet containing any specific configuration
information associated with that user.
6. The LX unit then grants the user the services requested.
Comentarios a estos manuales