User's Manual

Table Of Contents
114 Operation
Chapter 4 - Operation and Administration
4 When an SU attempt registering at the NPU, the NPU searches within its local
database whether this is a Permanent SU (defined in the database by its MAC
Address).
If the NPU recognizes the SU as a Permanent one, it provides the Local
(Permanent) Services as defined in the NPU's local database (see “Defining
Local (Permanent) Services” on page 236.
If the SU is not defined as Permanent in the NPU’s database, the NPU
queries the RADIUS server for SU authentication and service provisioning.
5 The RADIUS server searches for the corresponding Service defined for the SU
(based on the User Name and Password).
If it finds the applicable service(s) the RADIUS server replies to the NPU
with the Service parameters (Service Profile Name, VLAN List, Access VLAN
Configuration, VLAN Transparency Mode Option and VLAN Classification
Mode).
If the RADIUS server does not find matching SU’s credentials or defined
service(s), it replies to the NPU with a reject message.
6 According to the response from the RADIUS server, the NPU either
authenticates the SU and provides the appropriate service(s) or rejects the SU.
7 Part of the information sent from the RADIUS server can include the
Authentication Time Out. Before the end of this time the NPU should
re-authenticate the SU with the RADIUS server. This allows the operator to
stop service for a customer even if the SU was not reset and the network entry
process was not re-started.
A RADIUS server can be used for authentication purposes only, for accounting
purposes only, or for both authentication and accounting purposes. Up to two
servers of each type can be defined. Each server of each type
(Authentication/accounting) can be defined as either Primary or Secondary. Only
one server of each type can be defined as Primary. If two servers of a certain type
are defined, then upon first trial of an authentication/accounting transaction the
NPU will attempt to communicate with the Primary server of the relevant type
(provided the server’s Operation Status is Up). If it cannot communicate with the
Primary server, it will attempt communicating with the other server (and vice
versa). Upon succeeding to communicate with a certain server, this server is
defined as Active (and the other one as Standby). As long as the NPU succeeds to
communicate with an Active Authentication/Accounting server, it will continue
using it for authentication/accounting transactions.