Cisco Cisco Prime Optical 9.3 Riferimenti tecnici

Pagina di 14
 
6
Cisco Prime Optical 9.3 Basic External Authentication
OL-23465-01
RADIUS System Flow
3.
The Prime Optical server’s RADIUS client sends an Access-Request message to the RADIUS 
access server. The access server replies with an Access-Accept RADIUS message if the user 
credentials are accepted, with an Access-Reject if the user credentials are rejected, or with an 
Access-Challenge. For an Access-Challenge, the access server sends a human-readable request to 
the user; the Prime Optical client prompts the user with the request, collects the user response, and 
sends the response back to the Prime Optical server. The Prime Optical server sends a new 
Access-Request with the user’s response to the access server. This process continues cyclically until 
the access server sends an Access-Accept or Access-Reject RADIUS message. For details, see 
The following table describes the RADIUS attributes that Prime Optical server’s RADIUS client sends 
in Access-Request messages.
Table 2
Attributes That the Prime Optical Server’s RADIUS Client Sends in Access-Request Messages
RADIUS Attribute
Description
User-Name value
Prime Optical user’s name
User-Password value
Encrypted user’s password
NAS-IP-Address value
Prime Optical host’s IPv4 address
NAS-Identifier value
ctms
NAS-Port-Type value
5 (virtual)
Note
This attribute instructs the server to indicate that the user is not on a physical port.
NAS-Port value
Process ID of the RADIUS client
Service-Type value
8 (authenticate only)
Note
This attribute is present in the first Access-Request message, but is missing from 
the RADIUS server’s Access-Challenge replies. For this reason, the RADIUS 
server administrator must not configure the RADIUS server to check for the 
existence of this attribute in every Access-Request message.