ZyXEL Omni TA 128 User Guide - Page 51

Authentication conversion

Page 51 highlights

PPP HDLC framing is described in RFC1662. PPP over ISDN is described in RFC1618. Related command: • ATB40 - Async to Sync PPP conversion. Authentication conversion After a link is established, it is necessary to authenticate the peer for security reasons. There are two popular authentication methods. One is Password Authentication Protocol (PAP) and the other is Challenge Handshake Authentication Protocol (CHAP). PAP is less secure because it transmits the username/password in plain text form. Unlike PAP, CHAP transmits the username/password in coded form. Some ISPs may support CHAP as the only method for authentication. For those applications which do not support CHAP, the TA128 converts PAP into CHAP. By default, the PAP/CHAP conversion is always activated, so the authentication from the TA128 to PC is always PAP. That means you must configure your software to accept plain text as password authentication. Do not worry about password leakage, the TA128 will send the password out in hashed form by CHAP. Sometimes CHAP can not be supported by the ISP. You may set S87.2=1 to use PAP only. If you do not want to do authentication at all, set S118.3=1 to disable the conversion. O NOTE: Disabling authentication may cause problems in Windows 95. CHAP is described in RFC1994 and PAP is described in RFC1334. The only hash method supported by CHAP is MD5, MS-CHAP isn't supported yet. At this time authentication conversion works for clients only. Related commands: • ATS118.3 = 1 - Disable authentication conversion. • ATS118.3 = 0 - Enable authentication conversion depends on S87.2 (default). 39

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173

39
PPP HDLC framing is described in RFC1662. PPP over ISDN is
described in RFC1618.
Related command:
ATB40
- Async to Sync PPP conversion.
Authentication conversion
After a link is established, it is necessary to authenticate the peer
for security reasons. There are two popular authentication methods.
One is Password Authentication Protocol (PAP) and the other is
Challenge Handshake Authentication Protocol (CHAP). PAP is
less secure because it transmits the username/password in plain
text form. Unlike PAP, CHAP transmits the username/password in
coded form. Some ISPs may support CHAP as the only method
for authentication. For those applications which do not support
CHAP, the TA128 converts PAP into CHAP. By default, the
PAP/CHAP conversion is always activated, so the authentication
from the TA128 to PC is always PAP. That means you must
configure your software to accept plain text as password
authentication. Do not worry about password leakage, the TA128
will send the password out in hashed form by CHAP. Sometimes
CHAP can not be supported by the ISP. You may set S87.2=1 to
use PAP only. If you do not want to do authentication at all, set
S118.3=1 to disable the conversion.
O
NOTE
:
Disabling authentication may cause problems in Windows 95.
CHAP is described in RFC1994 and PAP is described in RFC1334.
The only hash method supported by CHAP is MD5, MS-CHAP
isn’t supported yet. At this time authentication conversion works
for clients only.
Related commands:
ATS118.3 = 1
- Disable authentication conversion.
ATS118.3 = 0
- Enable authentication conversion depends on
S87.2 (default).