
Configuring and Troubleshooting Bay Dial VPN Services
3-10 303509-A Rev 00
The BSAC (RADIUS) administrator at the customer’s site must enter one or more
IP address ranges to be used as a pool of assignable addresses. For each remote
user, the RADIUS administrator can enter either a specific IP address or allow the
assignment of an IP address from the pool. The administrator can, in fact, set up a
standard profile with “assign from pool” specified, and apply this profile to many
users at once.
The Current Users display identifies the active users and their assigned IP
addresses, so that the RADIUS administrator can tell which user has which
address. In addition, the administrator can release any assigned address that is no
longer in use by selecting that address and clicking on Clear. For more
information about assigning and managing IP addresses, see Configuring
RADIUS.
Assigning Addresses
All available IP addresses are in a queue. The first address in the queue is the first
one assigned. Released addresses return to the end of the queue for reassignment.
RADIUS saves all current address assignments in a database to prevent duplicate
address assignments if the server fails.
The gateway on the ISP network is a client of the RADIUS server on the
customer’s network; that is, it provides a service to the dial-in user, such as PPP or
Telnet
®
. The client is responsible for passing user information to the designated
RADIUS server. The RADIUS server receives the request and returns a response
to the client that it has successfully received the request.
The client and the RADIUS server authenticate the transactions between them
through the use of a shared secret, which is never sent over the network. Both
must be configured with the same secret for authentication to take place.
Each service that the NAS provides to a dial-in user constitutes a session; the
beginning of the session is the point at which service is first provided, and the end
of the session is the point at which the service ends. A user can have multiple
sessions in parallel or in series if the gateway supports that, with each session
generating a separate start and stop record with its own session ID. Figure 3-3
shows the sequence of events in dynamic IP address assignment.
Note:
Dynamic address assignment is not available for IPX.
Komentáře k této Příručce