Radius
Categoría:
Temas en este documento:
Protocolo RADIUS
Esta sección proporciona información sobre cómo AAA Gateway mapea los mensajes de control de acceso RADIUS para el protocolo RADIUS definido en RFC-2865 y RFC-2869.
Conformidad de la sección
La Tabla 1-1 a continuación enumera la información de conformidad para las secciones del protocolo RADIUS en RFC-2865.
Tabla 1-1: Conformidad de la sección RFC-2865
| Número de sección | Sección | Estado | Notas |
|---|---|---|---|
| 1 | Introduction | Not applicable | - |
| 1.1 | Specification of Requirements | Not applicable | - |
| 1.2 | Terminology | Not applicable | - |
| 2 | Operation | Partially supported | - |
| 2.1 | Challenge/Response | Supported | - |
| 2.2 | Interoperation with PAP and CHAP | Not supported | - |
| 2.3 | Proxy | Not applicable | - |
| 2.4 | Why UDP? | Not applicable | - |
| 2.5 | Retransmission Hints | Supported | - |
| 2.6 | Keep-Alives Considered Harmful | Supported | - |
| 3 | Packet Format | Supported | - |
| 4 | Packet Types | Supported | - |
| 4.1 | Access-Request | Supported | - |
| 4.2 | Access-Accept | Supported | - |
| 4.3 | Access-Reject | Supported | - |
| 4.4 | Access-Challenge | Supported | - |
| 5 | Attributes | Supported | - |
| 5.1 | User-Name | Supported | - |
| 5.2 | User-Password | Supported | - |
| 5.3 | CHAP-Password | Supported | - |
| 5.4 | NAS-IP-Address | Supported | - |
| 5.5 | NAS-Port | Supported | - |
| 5.6 | Service-Type | Supported | - |
| 5.7 | Framed-Protocol | Supported | - |
| 5.8 | Framed-IP-Address | Supported | - |
| 5.9 | Framed-IP-Netmask | Supported | - |
| 5.10 | Framed-Routing | Supported | - |
| 5.11 | Filter-Id | Supported | - |
| 5.12 | Framed-MTU | Supported | - |
| 5.13 | Framed-Compression | Supported | - |
| 5.14 | Login-IP-Host | Supported | - |
| 5.15 | Login-Service | Supported | - |
| 5.16 | Login-TCP-Port | Supported | - |
| 5.17 | (unassigned) | Supported | - |
| 5.18 | Reply-Message | Supported | - |
| 5.19 | Callback-Number | Supported | - |
| 5.20 | Callback-Id | Supported | - |
| 5.21 | (unassigned) | Supported | - |
| 5.22 | Framed-Route | Supported | - |
| 5.23 | Framed-IPX-Network | Supported | - |
| 5.24 | State | Supported | - |
| 5.25 | Class | Supported | - |
| 5.26 | Vendor-Specific | Supported | - |
| 5.27 | Session-Timeout | Supported | - |
| 5.28 | Idle-Timeout | Supported | - |
| 5.29 | Termination-Action | Supported | - |
| 5.30 | Called-Station-Id | Supported | - |
| 5.31 | Calling-Station-Id | Supported | - |
| 5.32 | NAS-Identifier | Supported | - |
| 5.33 | Proxy-State | Supported | - |
| 5.34 | Login-LAT-Service | Supported | - |
| 5.35 | Login-LAT-Node | Supported | - |
| 5.36 | Login-LAT-Group | Supported | - |
| 5.37 | Framed-AppleTalk-Link | Supported | - |
| 5.38 | Framed-AppleTalk-Network | Supported | - |
| 5.39 | Framed-AppleTalk-Zone | Supported | - |
| 5.40 | CHAP-Challenge | Supported | - |
| 5.41 | NAS-Port-Type | Supported | - |
| 5.42 | Port-Limit | Supported | - |
| 5.43 | Login-LAT-Port | Supported | - |
| 5.44 | Table of Attributes | Supported | - |
| 6 | IANA Considerations | No requirement | - |
| 6.1 | Definition of Terms | No requirement | - |
| 6.2 | Recommended Registration Policies | No requirement | - |
| 7 | Examples | Supported | - |
| 7.1 | User Telnet to Specified Host | Supported | - |
| 7.2 | Framed User Authenticating with CHAP | Supported | - |
| 7.3 | User with Challenge-Response card | Not supported | - |
| 8 | Security Considerations | Not supported | - |
| 9 | Change Log | No requirement | - |
| 10 | References | No requirement | - |
| 11 | Acknowledgements | No requirement | - |
| 12 | Chair’s Address | No requirement | - |
| 13 | Authors’ Addresses | No requirement | - |
| 14 | Full Copyright Statement | No requirement | - |
La siguiente Tabla 1-2 proporciona una lista de la información de conformidad para las secciones del protocolo RADIUS en RFC-2869.
Tabla 1-2: Conformidad de la sección RFC-2869
| Número de sección | Sección | Estado | Notas |
|---|---|---|---|
| 1 | Introduction | Not applicable | - |
| 1.1 | Specification of Requirements | Not applicable | - |
| 1.2 | Terminology | Not applicable | - |
| 2 | Operation | Partially supported | - |
| 2.1 | RADIUS support for Interim Accounting Updates | Not supported | - |
| 2.2 | RADIUS support for Apple Remote Access Protocol | Not supported | - |
| 2.3 | RADIUS Support for Extensible Authentication Protocol (EAP) | Supported | - |
| 2.3.1 | Protocol Overview | Supported | - |
| 2.3.2 | Retransmission | Supported | - |
| 2.3.3 | Fragmentation | Not supported | - |
| 2.3.4 | Examples | Supported | - |
| 2.3.5 | Alternative Uses | Supported | - |
| 3 | Packet Format | Supported | - |
| 4 | Packet Types | Supported | - |
| 5 | Attributes | Partially supported | - |
| 5.1 | Acct-Input-Gigawords | Not supported | - |
| 5.2 | Acct-Output-Gigawords | Not supported | - |
| 5.3 | Event-Timestamp | Not supported | - |
| 5.4 | ARAP-Password | Not supported | - |
| 5.5 | ARAP-Features | Not supported | - |
| 5.6 | ARAP-Zone-Access | Not supported | - |
| 5.7 | ARAP-Security | Not supported | - |
| 5.8 | ARAP-Security-Data | Not supported | - |
| 5.9 | Password-Retry | Not supported | - |
| 5.10 | Prompt | Not supported | - |
| 5.11 | Connect-Info | Not supported | - |
| 5.12 | Configuration-Token | Not supported | - |
| 5.13 | EAP-Message | Supported | - |
| 5.14 | Message-Authenticator | Supported | - |
| 5.15 | ARAP-Challenge-Response | Not supported | - |
| 5.16 | Acct-Interim-Interval | Not supported | - |
| 5.17 | NAS-Port-Id | Supported | - |
| 5.18 | Framed-Pool | Not supported | - |
| 5.19 | Table of Attributes | Not supported | - |
| 6 | IANA Considerations | No requirement | - |
| 7 | Security Considerations | Supported | - |
| 7.1 | Message-Authenticator Security | Supported | - |
| 7.2 | EAP Security | Supported | - |
| 7.2.1 | Separation of EAP server and PPP authenticator | Not supported | - |
| 7.2.2 | Connection hijacking | Not supported | - |
| 7.2.3 | Man in the middle attacks | Not supported | - |
| 7.2.4 | Multiple databases | Not supported | - |
| 7.2.5 | Negotiation attacks | Not supported | - |
| 8 | References | No requirement | - |
| 9 | Acknowledgements | No requirement | - |
| 10 | Chair’s Address | No requirement | - |
| 11 | Authors’ Addresses | No requirement | - |
| 12 | Full Copyright Statement | No requirement | - |
AVPs de Access-Request
Aquí hay una Tabla 1-3 con la información de conformidad para los pares atributo-valor (AVP (ang. Attribute-Value Pair)) de Access-Request.
Tabla 1-3: AVPs de Access-Request
| AVP de RADIUS | Estado | Notas |
|---|---|---|
| User-Name | Supported | - |
| User-Password | Supported | - |
| CHAP-Password | Supported | - |
| CHAP-Challenge | Supported | - |
| NAS-IP-Address | Supported | - |
| NAS-Port | Supported | - |
| NAS-Port-Type | Supported | - |
| NAS-Identifier | Supported | - |
| Service-Type | Supported | - |
| Framed-Protocol | Supported | - |
| Framed-IP-Address | Supported | - |
| Framed-IP-Netmask | Supported | - |
| Framed-MTU | Supported | - |
| Framed-Compression | Supported | - |
| Login-IP-Host | Supported | - |
| Callback-Number | Supported | - |
| Called-Station-Id | Supported | - |
| Calling-Station-Id | Supported | - |
| State | Supported | - |
| Proxy-State | Supported | - |
| Login-LAT-Service | Supported | - |
| Login-LAT-Node | Supported | - |
| Login-LAT-Group | Supported | - |
| Login-LAT-Port | Supported | - |
| Vendor-Specific | Supported | - |
| EAP-Message | Supported | - |
| Message-Authenticator | Supported | - |
AVPs de Access-Accept
A continuación se muestra la información de conformidad para los AVPs de Access-Accept.
Tabla 1-4: AVPs de Access-Accept
| AVP de RADIUS | Estado | Notas |
|---|---|---|
| User-Name | Supported | - |
| Service-Type | Supported | - |
| Framed-Protocol | Supported | - |
| Framed-IP-Address | Supported | - |
| Framed-IP-Netmask | Supported | - |
| Framed-Routing | Supported | - |
| Framed-Route | Supported | - |
| Framed-IPX-Network | Supported | - |
| Framed-AppleTalk-Link | Supported | - |
| Framed-AppleTalk-Network | Supported | - |
| Framed-AppleTalk-Zone | Supported | - |
| Filter-Id | Supported | - |
| Framed-MTU | Supported | - |
| Framed-Compression | Supported | - |
| Login-IP-Host | Supported | - |
| Login-Service | Supported | - |
| Login-TCP-Port | Supported | - |
| Reply-Message | Supported | - |
| Callback-Number | Supported | - |
| Callback-Id | Supported | - |
| Class | Supported | - |
| Session-Timeout | Supported | - |
| Idle-Timeout | Supported | - |
| Termination-Action | Supported | - |
| State | Supported | - |
| Proxy-State | Supported | - |
| Login-LAT-Service | Supported | - |
| Login-LAT-Node | Supported | - |
| Login-LAT-Group | Supported | - |
| Login-LAT-Port | Supported | - |
| Port-Limit | Supported | - |
| Vendor-Specific | Supported | - |
| Acct-Session-Id | Supported | - |
| EAP-Message | Supported | - |
| Message-Authenticator | Supported | - |
AVPs de Access-Reject
La Tabla 1-5 tiene una lista de la información de conformidad para los AVPs de Access-Reject.
Tabla 1-5: AVPs de Access-Reject
| AVP de RADIUS | Estado | Notas |
|---|---|---|
| User-Name | Supported | - |
| Reply-Message | Supported | - |
| Class | Supported | - |
| Proxy-State | Supported | - |
| Vendor-Specific | Supported | - |
| Acct-Session-Id | Supported | - |
| EAP-Message | Supported | - |
| Message-Authenticator | Supported | - |
AVPs de Access-Challenge
La Tabla 1-6 contiene la información de conformidad para los AVPs de Access-Challenge.
Tabla 1-6: AVPs de Access-Challenge
| AVP de RADIUS | Estado | Notas |
|---|---|---|
| Reply-Message | Supported | - |
| Session-Timeout | Supported | - |
| Idle-Timeout | Supported | - |
| State | Supported | - |
| Proxy-State | Supported | - |
| Vendor-Specific | Supported | - |
| EAP-Message | Supported | - |
| Message-Authenticator | Supported | - |
Protocolo de contabilidad RADIUS
Esta sección proporciona detalles sobre cómo AAA Gateway mapea los mensajes de contabilidad RADIUS para el protocolo RADIUS definido en RFC-2866.
Conformidad de la sección
A continuación se muestra una lista de la información de conformidad para las secciones del protocolo de contabilidad RADIUS en RFC-2866.
Tabla 2-1: Conformidad de la sección RFC-2866
| Número de sección | Sección | Estado | Notas |
|---|---|---|---|
| 1 | Introduction | Not applicable | - |
| 1.1 | Specification of Requirement | Not applicable | - |
| 1.2 | Terminology | Not applicable | - |
| 2 | Operation | Supported | - |
| 2.1 | Proxy | Not supported | - |
| 3 | Packet Format | Supported | - |
| 4 | Packet Types | Supported | - |
| 4.1 | Accounting-Request | Supported | - |
| 4.2 | Accounting-Response | Supported | - |
| 5 | Attributes | Supported | - |
| 5.1 | Acct-Status-Type | Supported | - |
| 5.2 | Acct-Delay-Time | Supported | - |
| 5.3 | Acct-Input-Octets | Supported | - |
| 5.4 | Acct-Output-Octets | Supported | - |
| 5.5 | Acct-Session-Id | Supported | - |
| 5.6 | Acct-Authentic | Supported | - |
| 5.7 | Acct-Session-Time | Supported | - |
| 5.8 | Acct-Input-Packets | Supported | - |
| 5.9 | Acct-Output-Packets | Supported | - |
| 5.10 | Acct-Terminate-Cause | Supported | - |
| 5.11 | Acct-Multi-Session-Id | Supported | - |
| 5.12 | Acct-Link-Count | Supported | - |
| 5.13 | Table of Attributes | Supported | - |
| 6 | IANA Considerations | Supported | - |
| 7 | Security Considerations | Supported | - |
| 8 | Change Log | Not applicable | - |
| 9 | References | No Requirement | - |
| 10 | Acknowledgements | No requirement | - |
AVPs de Accounting-Request
La siguiente tabla contiene la descripción de cómo ECE admite los pares atributo-valor (AVP) de Accounting-Request.
Tabla 2-2: AVPs de Accounting-Request
| AVP de contabilidad RADIUS | Estado | Notas |
|---|---|---|
| User-Name | Supported | Este es un AVP obligatorio. |
| NAS-IP-Address | Supported | Este es un AVP obligatorio. |
| NAS-Identifier | Supported | Este es un AVP obligatorio. |
| NAS-Port-Type | Supported | - |
| Class | Supported | - |
| Service-Type | Supported | - |
| Framed-Protocol | Supported | - |
| Framed-IP-Address | Supported | - |
| Framed-IP-Netmask | Supported | - |
| Framed-MTU | Supported | - |
| Framed-Compression | Supported | - |
| Login-IP-Host | Supported | - |
| Callback-Number | Supported | - |
| Called-Station-Id | Supported | - |
| Calling-Station-Id | Supported | - |
| Proxy-State | Supported | - |
| Login-LAT-Service | Supported | - |
| Login-LAT-Node | Supported | - |
| Login-LAT-Group | Supported | - |
| Login-LAT-Port | Supported | - |
| CHAP-Challenge | Supported | - |
| Acct-Status-Type | Supported | Este es un AVP obligatorio. |
| Acct-Delay-Time | Supported | - |
| Acct-Input-Octets | Supported | - |
| Acct-Output-Octets | Supported | - |
| Acct-Session-Id | Supported | Este es un AVP obligatorio. |
| Acct-Authentic | Supported | - |
| Acct-Session-Time | Supported | - |
| Acct-Input-Packets | Supported | - |
| Acct-Output-Packets | Supported | - |
| Acct-Terminate-Cause | Supported | - |
| Acct-Multi-Session-Id | Supported | - |
| Acct-Link-Count | Supported | - |
| Vendor-Specific | Supported | - |
AVPs de Accounting-Response
El mensaje de Accounting-Response no tiene ningún AVP.
Protocolo de desconexión RADIUS
Esta sección describe cómo AAA Gateway mapea los mensajes de desconexión RADIUS para el protocolo RADIUS definido en RFC-3576.
Conformidad de la sección
A continuación se muestra la información de conformidad para las secciones del protocolo de desconexión RADIUS en RFC-3576.
Tabla 3-1: Conformidad de la sección RFC-3576
| Número de sección | Sección | Estado | Notas |
|---|---|---|---|
| 1 | Introduction | - | - |
| 1.1 | Applicability | - | - |
| 1.2 | Requirements Language | - | - |
| 1.3 | Terminology | - | - |
| 2 | Overview | - | - |
| 2.1 | Disconnect Messages (DM) | - | - |
| 2.2 | Change-of-Authorization Messages (CoA) | - | - |
| 2.3 | Packet Format | - | - |
| 3 | Attributes | - | - |
| 3.1 | Error-Cause | - | - |
| 3.2 | Table of Attributes | - | - |
| 4 | IANA Considerations | - | - |
| 5 | Security Considerations | - | - |
| 5.1 | Authorization Issues | - | - |
| 5.2 | Impersonation | - | - |
| 5.3 | IPsec Usage Guidelines | - | - |
| 5.4 | Replay Protection | - | - |
| 6 | Example Traces | - | - |
| 7 | References | - | - |
| 7.1 | Normative References | - | - |
| 7.2 | Informative References | - | - |
| 8 | Intellectual Property Statement | - | - |
| 9 | Acknowledgements | - | - |
| 10 | Author’s Addresses | - | - |
| 11 | Full Copyright Statement | - | - |
AVPs de Disconnect-Request
La siguiente Tabla 3-2 enumera la información de conformidad para los AVPs de Disconnect-Request.
Tabla 3-2: AVPs de Disconnect-Request
| AVP de RADIUS | Estado | Notas |
|---|---|---|
| User-Name | Supported | - |
| User-Password | Supported | - |
| CHAP-Password | Supported | - |
| CHAP-Challenge | Supported | - |
| NAS-IP-Address | Supported | - |
| NAS-Port | Supported | - |
| NAS-Port-Type | Supported | - |
| NAS-Identifier | Supported | - |
| Service-Type | Supported | - |
| Framed-Protocol | Supported | - |
| Framed-IP-Address | Supported | - |
| Framed-IP-Netmask | Supported | - |
| Framed-MTU | Supported | - |
| Framed-Compression | Supported | - |
| Login-IP-Host | Supported | - |
| Callback-Number | Supported | - |
| Called-Station-Id | Supported | - |
| Calling-Station-Id | Supported | - |
| State | Supported | - |
| Proxy-State | Supported | - |
| Login-LAT-Service | Supported | - |
| Login-LAT-Node | Supported | - |
| Login-LAT-Group | Supported | - |
| Login-LAT-Port | Supported | - |
| Vendor-Specific | Supported | - |
| EAP-Message | Supported | - |
| Message-Authenticator | Supported | - |
AVPs de Disconnect-Response
El mensaje Disconnect-Response no tiene AVPs.