Ascend Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: (ASCEND) Problem with CLID/CHAP-PAP and RADIUS



At 01:30 AM 5/18/97 +0100, Rui Duarte Bastos wrote:
>Hi Ascenders
>
>  I've been searching around some info about the authentication using
>CLID/PAP or CHAP. Since I wasn't able to get it working last week I'd
>apreciate some info from guys that have it working.
>
>  As far as I found the ID Auth options under MAXs 5.0 series work this
>way:
>
>   - Ignore   CLID isn't used
>   - Require  only clid is used authentication. If CLID isn't available
>              the call isn't answered (or is rejected?)
>   - Prefer   If CLID is available it is used for authentication. If
>              there is no profile with this CLID the call is rejected.
>              If no CLID is available then normal PAP/CHAP takes place.
>   - Fallback Don't know how it works

Here's the logic of PREFER:

	If NO CLID - try authentication.

	If there is CLID do the following:

		1) Check Local Profiles

		2) If no Local Profile, Check RADIUS

		3) if RADIUS Times out
			then check to see if the AuthReq Flag is set.
			If AuthReq=True (default) then dont answer the call,
			if AuthReq=False, then continue to authentication.

		   if RADIUS returns and doesn't match CLID
			drop the call

Fallback is authenticate using the CLID when RADIUS is available, otherwise
fall back to using password authentication.

And yes, I would recommend loading a more recent version of Radius. Perhaps
it would also be best to test drive Ascend Access Control.


Matt Holdrege  -  http://www.ascend.com  -  matt@ascend.com
++ Ascend Users Mailing List ++
To unsubscribe:	send unsubscribe to ascend-users-request@bungi.com
To get FAQ'd:	<http://www.shore.net/~dreaming/ascend-faq>
or		<ftp://ftp.shore.net/members/dreaming/ascend-faq.txt>


References: