
Implementation Notes for All Dial Services
308621-14.00 Rev 00
5-3
For CHAP, Router A initiates a CHAP challenge and Router B responds. Router
A responds with a response match and the connection is activated. Router B can
also initiate a CHAP challenge. For PAP, Router A sends an authenticate request
to Router B. Router B sends an authenticate response and then activates the
connection. Router B can also initiate an authenticate request.
Both Routers A and B can use PAP and CHAP in a single line pool. If Router B
rejects the CHAP challenge, and Router A has the PAP Fallback parameter
enabled, Router A switches to PAP and retries the authentication.
One-Way Authentication
Figure 5-2
illustrates one-way authentication. For CHAP or PAP, the calling router
does not try to authenticate the called router, but it does recognize and respond to
CHAP challenges or PAP authentication requests from the called router. The
called router does authenticate the calling router. Using one-way authentication,
the router can communicate with other devices that may not support two-way
authentication.
Figure 5-2. One-Way Authentication
Router A Router B
Challenge
Response match
Response
One-Way Authentication -- CHAP
Calling router
Called router
(outbound authentication disabled)
Router A Router B
Authenticate request
Authenticate response
One-Way Authentication -- PAP
Calling router
Called router
(outbound authentication disabled)
DS0031A
Comentarios a estos manuales