
Dial VPN Layer 3 Tunneling
303509-A Rev 00 3-5
The Grant message contains the following information, which is stored in the
TMS database:
• Remote node’s domain name
• Domain name information server (DNIS) -- for Model 8000/5399 platforms,
the DNIS is the called number; for other platforms, it is 0 (zero)
• Home agent’s IP address on the gateway (the IP address of the gateway end of
the IP tunnel)
• Current number of users
• Type of connection between the ISP network’s edge router or gateway and the
CPE router on the remote node’s home network
• Primary and secondary RADIUS server IP addresses
• Authentication protocol information
For each tunnel user, the NAS sends this information to the RADIUS client on the
gateway, which in turn sends an authentication and address request to the
RADIUS server on the remote node’s home network. When the RADIUS server
responds, authenticating the user, the NAS establishes the tunnel.
Tunnel Management in an All-RADIUS Network
The all-RADIUS solution integrates the TMS database functions into the
RADIUS server that resides on the service provider network. This RADIUS
server recognizes the format of the VPN identifier in the user name and returns
tunnel information to the NAS. The NAS uses the tunnel information to establish
a connection to the gateway. Once the connection is made, the user authentication
information is forwarded to the indicated authentication server.
Refer to Chapter 5 for more information about the contents of the TMS database.
Note:
The default value for the DNIS is 0. The NAS administrator can change
this value.
Komentáře k této Příručce