
Implementation Notes for All Dial Services
114062 Rev. A 3-3
Both Router A and B can use PAP and CHAP in a single line pool. If
Router B rejects the CHAP challenge, and Router A has the PAP Fallback
parameter enabled, Router A switches to PAP and reattempts the authentication.
For PAP, Router A sends an Authenticate Request to Router B, which then
responds. The connection is then activated.
One-Way Authentication
Figure 3-2 shows an example of one-way authentication. For CHAP or PAP, the
router placing the call disables the authentication protocol for the circuit, while
the router on the receiving side enables authentication. Although the calling router
disables authentication, it still recognizes and responds to CHAP challenges or
PAP authentication requests. Disabling outbound authentication enables the router
to interoperate with other devices that may not support two-way authentication.
Figure 3-2. One-Way Authentication
Router A Router B
Challenge
Response Match
Response
One-Way Authentication -- CHAP
Calling Router
Receiving Router
Outbound Authentication Disabled
Router A Router B
Authenticate-Request
Authenticate Response
One-Way Authentication -- PAP
Calling Router
Receiving Router
Outbound Authentication Disabled
DS0031A
Comentarios a estos manuales