Configuring bidirectional chap on the max unit, Configuring bidirectional chap on the max unit -64 – Lucent Technologies 6000 User Manual

Page 196

Advertising
background image

4-64

MAX 6000/3000 Network Configuration Guide

Configuring Individual WAN Connections
Configuring bidirectional CHAP support

For incoming calls, the MAX first challenges the caller for its username and password, then the
MAX compares the username and password to those in Connection profiles or RADIUS
profiles. A user can have either a Connection profile defined or a RADIUS profile defined, but
not both. For outgoing calls, the MAX dials the called device and it is the caller’s
responsibility to challenge the MAX for authentication.

Configuring bidirectional CHAP on the MAX unit

Set up the directional CHAP for all or selected incoming calls and for outgoing calls. For
authentication of incoming calls, the MAX sends its system name unless you specify a
different name.

Setting up bidirectional CHAP on the MAX unit for all incoming calls

Figure 4-9 shows a configuration in which a MAX unit and its dial-in clients authenticate each
other by means of bidirectional CHAP. One or more clients can dial into the MAX unit. The
MAX unit authenticates the calling device by means of a Connection profile, and each dial-in
client authenticates the MAX unit by means of the Send PW value.

Figure 4-9. Bidirectional CHAP for all incoming calls to the MAX unit

To configure bidirectional CHAP on the MAX unit for all incoming calls, proceed as follows:

1

Open the Ethernet > Answer > PPP Options submenu.

2

Set the Receive Auth parameter to Either, CHAP, or MS-CHAP.

3

Set the Bi-Dir Auth parameter to Required or Allowed. Required specifies that
bidirectional authentication must be carried out or the call is dropped. Allowed specifies
that authentication can be bidirectional. The MAX unit identifies the calling device, and
the calling device can identify the MAX unit, but the calling device need not do so for the
call to be accepted.

4

Exit the profile and, at the exit prompt, select the exit and accept option.

5

For each incoming call, open a Ethernet > Connections > Connection profile > Encaps
Options subprofile.

6

Set the Send PW parameter to any text string. The password you specify is the one sent to
the calling unit during the authentication initiated by the calling unit.

7

Set the Recv PW parameter to any text string. The password you specify is the one sent by
the calling unit during the authentication initiated by the MAX unit.

8

Exit the profile and, at the exit prompt, select the exit and accept option.

Note:

When you set the Recv-Auth parameter to Any, the MAX unit can accept both PAP and

CHAP authentication. The Bi-Dir Auth setting will be used only if a form of CHAP
authentication has been negotiated during LCP negotiation. If any form of PAP authentication

WAN

Pipeline unit

MAX unit

Dial-in clients

Send PW sent

Recv PW sent

Advertising
This manual is related to the following products: