R0106-HP MSR Router Series Security Configuration Guide(V7)
453
packet. The HTTP Redirect packet contains a redirect URI and requires the client to terminate the
TCP connection.
3. After receiving the HTTP Redirect packet, the client terminates the TCP connection and then
establishes a new TCP connection with the authenticator.
4. When the authenticator receives the HTTP Get packet, it performs the second redirection
verification. The authenticator verifies the following information:
{ The client has passed the first redirection verification.
{ The URI in the HTTP Get packet is the redirect URI.
5. If the client passes the second redirection verification, the authenticator adds its IP address to the
trusted IP list, and responds a Redirect packet. The Redirect packet contains the URI that the client
originally carried.
6. The authenticator directly forwards the trusted client's subsequent packets to the server.
Figure 141 HTTP client verification process