Configuring ms-chap or ms-chap-v2 authentication, Configuring ms-chap or, Ms-chap-v2 authentication – H3C Technologies H3C SecPath F1000-E User Manual

Page 143

Advertising
background image

118

Step

Command

Remarks

9.

Create an ISP domain, or enter an
existing ISP domain view.

domain isp-name

Optional.
To configure the ppp

authentication-mode
command with an ISP

domain specified which is

not the default domain

system, configure this
command before

configuring the ppp

authentication-mode
command.

10.

Configure local authentication for

the PPP users.

authentication ppp local

Optional.

NOTE:

For more information about local user configuration and domain configuration, see

Access Control

Configuration Guide.

To configure the authenticatee:

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Create a VT interface and
enter its view.

interface virtual-template number N/A

3.

Assign a username to the

CHAP authenticatee.

ppp chap user username

The username you assign to the
authenticatee must be the same as

the local username you assign to
the authenticatee on the

authenticator.

4.

Set the default CHAP
authentication password.

ppp chap password { cipher |
simple } password

The password you set for the
authenticatee must be the same as

the password you set for the
authenticatee on the authenticator.

Configuring MS-CHAP or MS-CHAP-V2

authentication

NOTE:

In MS-CHAP or MS-CHAP-V2 authentication, a H3C device can only be an authenticator

L2TP supports the MS-CHAP authentication but does not support the MS-CHAP-V2 authentication.

Password change in MS-CHAP-V2 authentication does not support local authentication, but is used only
in RADIUS authentication.

To configure the authenticator for MS-CHAP or MS-CHAP-V2 authentication:

Advertising