
Configuring and Troubleshooting Bay Dial VPN Services
5-12 303509-A Rev 00
Configuring Local Authentication Using the ACP
Dial VPN relies on the remote authentication (RADIUS) server at the destination
site to authenticate dial-in users. If you are configuring an erpcd-based network
and you want to use local authentication (that is, within the Dial VPN service
provider network), the acp_regime file must contain the line
<path> /acp_passwd
. You must also configure the Access Control Protocol
(ACP) authentication server, as follows:
1.
Using CHAP for local ACP authentication, create an ACP file called
acp_userinfo
(by default in the
/usr/annex
directory):
acp_userinfo for CHAP
The following is a sample entry for the acp_userinfo:
user sample1
chap_secret annex
end
2.
Similarly, if you are using PAP, you create a file called
acp_passwd
for
PAP:
acp_passwd for PAP
If you are using CHAP as your authentication protocol, set the PAP password
only if you enable CHAP with PAP fallback. The following sample entry
shows an encrypted ACP password for PAP:
sample1:IQ3Qo0HXrsUoM:501:500:& sample1:/users/user1:/bin/csh
The user cannot enter a password directly. To enter a password, use the
ch_passwd
utility. The acp_password file uses the same format as the
/etc/passwd file.
3.
Set the dialup addresses in the
acp_dialup
file for IP and IPX addresses,
as shown in the following sample entry:
sample1 * 128.128.129.181<---- IP Address
sample1 * 013ABC0:~<---- IP Network Address
Note:
In addition to the parameters listed in Table 5-2, the
show
command
also displays accounting parameters.
Comentarios a estos manuales