HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 12

Basic RADIUS packet exchange process

Page 12 highlights

Basic RADIUS packet exchange process Figure 3 illustrates the interactions between a user host, the RADIUS client, and the RADIUS server. Figure 3 Basic RADIUS packet exchange process RADIUS operates in the following manner: 1. The host sends a connection request that includes the user's username and password to the RADIUS client. 2. The RADIUS client encrypts the user password by using the MD5 algorithm, the shared key, and some other information, encapsulates the username and the encrypted password to an authentication request (Access-Request), and sends the request to the RADIUS server. 3. The RADIUS server authenticates the username and password. If the authentication succeeds, the server sends back an Access-Accept packet that contains the user's authorization information. If the authentication fails, the server returns an Access-Reject packet. 4. The RADIUS client permits or denies the user according to the authentication result. If it permits the user, it sends a start-accounting request (Accounting-Request) packet to the RADIUS server. 5. The RADIUS server returns an acknowledgement (Accounting-Response) packet and starts accounting. 6. The user accesses the network resources. 7. The host requests the RADIUS client to tear down the connection. 8. The RADIUS client sends a stop-accounting request (Accounting-Request) packet to the RADIUS server. 9. The RADIUS server returns an acknowledgement (Accounting-Response) and stops accounting for the user. 10. The RADIUS client notifies the user of the termination. 3

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

3
Basic RADIUS packet exchange process
Figure 3
illustrates the interactions between a user host, the RADIUS client, and the RADIUS server.
Figure 3
Basic RADIUS packet exchange process
RADIUS operates in the following manner:
1.
The host sends a connection request that includes the user's username and password to the
RADIUS client.
2.
The RADIUS client encrypts the user password by using the MD5 algorithm, the shared key, and
some other information, encapsulates the username and the encrypted password to an
authentication request (Access-Request), and sends the request to the RADIUS server.
3.
The RADIUS server authenticates the username and password. If the authentication succeeds, the
server sends back an Access-Accept packet that contains the user's authorization information. If
the authentication fails, the server returns an Access-Reject packet.
4.
The RADIUS client permits or denies the user according to the authentication result. If it permits the
user, it sends a start-accounting request (Accounting-Request) packet to the RADIUS server.
5.
The RADIUS server returns an acknowledgement (Accounting-Response) packet and starts
accounting.
6.
The user accesses the network resources.
7.
The host requests the RADIUS client to tear down the connection.
8.
The RADIUS client sends a stop-accounting request (Accounting-Request) packet to the RADIUS
server.
9.
The RADIUS server returns an acknowledgement (Accounting-Response) and stops accounting for
the user.
10.
The RADIUS client notifies the user of the termination.