Radius packet format – H3C Technologies H3C WX6000 Series Access Controllers User Manual

Page 438

Advertising
background image

38-3

Figure 38-2 Basic message exchange process of RADIUS

RADIUS client

RADIUS server

1) Username and password

3) Access-Accept/Reject

2) Access-Request

4) Accounting-Request (start)

5) Accounting-Response

7) Accounting-Request (stop)

8) Accounting-Response

9) Notification of access termination

Host

6) The host accesses the resources

The following is how RADIUS operates:

1) The host initiates a connection request carrying the username and password to the RADIUS client.

2) Having received the username and password, the RADIUS client sends an authentication request

(Access-Request) to the RADIUS server, with the user password encrypted by using the

Message-Digest 5 (MD5) algorithm and the shared key.

3) The RADIUS server authenticates the username and password. If the authentication succeeds, it

sends back an Access-Accept message containing the user’s authorization information. If the

authentication fails, it returns an Access-Reject message.

4) The RADIUS client permits or denies the user according to the returned authentication result. If it

permits the user, it sends a start-accounting request (Accounting-Request) to the RADIUS server.

5) The RADIUS server returns a start-accounting response (Accounting-Response) and starts

accounting.

6) The user accesses the network resources.

7) The host requests the RADIUS client to tear down the connection and the RADIUS client sends a

stop-accounting request (Accounting-Request) to the RADIUS server.

8) The RADIUS server returns a stop-accounting response (Accounting-Response) and stops

accounting for the user.

9) The user stops access to network resources.

RADIUS Packet Format

RADIUS uses UDP to transmit messages. It ensures the smooth message exchange between the

RADIUS server and the client through a series of mechanisms, including the timer management

mechanism, retransmission mechanism, and slave server mechanism.

Figure 38-3

shows the RADIUS

packet format.

Advertising