09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

persephone(config-if)#service-module t1 linecode b8zs<br />

persephone(config-if)#service-module t1 timeslots 1–24<br />

persephone(config-if)#service-module t1 clock source<br />

persephone(config-if)#ppp au<strong>the</strong>ntication chap<br />

Configuring PPP Encapsulation and Au<strong>the</strong>ntication<br />

PPP is IOS's open systems alternative Layer 2 encapsulation pro<strong>to</strong>col. PPP provides<br />

data-link encapsulation for synchronous and asynchronous serial and ISDN BRI<br />

interfaces. Like HDLC, PPP can transport any IOS-supported Layer 3 <strong>network</strong><br />

pro<strong>to</strong>col. To enable PPP encapsulation, <strong>the</strong> interface configuration subcommand<br />

is used.<br />

One of <strong>the</strong> many virtues of PPP is its built-in pro<strong>to</strong>col level au<strong>the</strong>ntication. This<br />

makes it <strong>the</strong> ideal pro<strong>to</strong>col for use with DDR and remote access over dial <strong>network</strong>ing<br />

scenarios. PPP supports two au<strong>the</strong>ntication mechanisms: Password Au<strong>the</strong>ntication<br />

Pro<strong>to</strong>col (PAP) and Challenge-response Au<strong>the</strong>ntication Pro<strong>to</strong>col (CHAP). These pro<br />

<strong>to</strong>cols do not participate in <strong>the</strong> au<strong>the</strong>ntication; <strong>the</strong>y only transport <strong>the</strong><br />

au<strong>the</strong>ntication credentials. The host/router is responsible for determining if actual<br />

access is permitted.<br />

The PAP au<strong>the</strong>ntication pro<strong>to</strong>col provides a mechanism for PPP peers <strong>to</strong> send<br />

au<strong>the</strong>ntication information <strong>to</strong> one ano<strong>the</strong>r. When a PPP connection is established,<br />

<strong>the</strong> initiating router sends a "clear text" username and password <strong>to</strong> <strong>the</strong> host router.<br />

If <strong>the</strong> username and password are correct, <strong>the</strong> session establishment is finished and<br />

<strong>the</strong> link is established. To enable PAP au<strong>the</strong>ntication on an ISDN BRI, async, or<br />

dialer interface, use <strong>the</strong> following steps:<br />

1. Enable PPP encapsulation.<br />

2. Enable PPP PAP au<strong>the</strong>ntication using .<br />

3. Configure <strong>the</strong> PAP username and password <strong>the</strong> interface will send <strong>to</strong> <strong>the</strong> host<br />

router. This is done with <strong>the</strong> command.<br />

If you have au<strong>the</strong>ntication and authorization enabled for PPP, <strong>the</strong><br />

username and password can be verified by whatever mechanism you have<br />

indicated—RADIUS, TACACS, or local. If you have old-mode (<strong>the</strong> IOS default)<br />

au<strong>the</strong>ntication, <strong>the</strong> username and password must be configured on <strong>the</strong> host router.<br />

Here is an example using an DDR async interface:<br />

asbr-a2(config)#int async 1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!