Cisco PIX 525 Spécifications Page 165

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 164
4-13
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 4 Using PIX Firewall in SOHO Networks
Using the PIX Firewall PPPoE Client
PPPoE provides a standard method of employing the authentication methods of the Point-to-Point
Protocol (PPP) over an Ethernet network. When used by ISPs, PPPoE allows authenticated assignment
of IP addresses. In this type of implementation, the PPPoE client and server are interconnected by Layer
2 bridging protocols running over a DSL or other broadband connection.
PPPoE is composed of two main phases:
Active Discovery Phase—In this phase, the PPPoE client locates a PPPoE server, called an access
concentrator. During this phase, a Session ID is assigned and the PPPoE layer is established.
PPP Session Phase—In this phase, PPP options are negotiated and authentication is performed.
Once the link setup is completed, PPPoE functions as a Layer 2 encapsulation method, allowing data
to be transferred over the PPP link within PPPoE headers.
At system initialization, the PPPoE client establishes a session with the access concentrator by
exchanging a series of packets. Once the session is established, a PPP link is set up, which includes
authentication using Password Authentication protocol (PAP). Once the PPP session is established, each
packet is encapsulated in the PPPoE and PPP headers.
Configuring the PPPoE Client Username and Password
To configure the username and password used to authenticate the PIX Firewall to the access
concentrator, use the PIX
Firewall vpdn command. The vpdn command is used to enable remote access
protocols, such as L2TP, PPTP, and PPPoE. To use the vpdn command, you first define a VPDN group
and then create individual users within the group.
To configure a PPPoE username and password, perform the following steps:
Step 1 Define the VPDN group to be used for PPPoE, by entering the following command:
vpdn group group_name request dialout pppoe
In this command, replace group_name with a descriptive name for the group, such as “pppoe-sbc.
Step 2 If your ISP requires authentication, select an authentication protocol by entering the following
command:
vpdn group group_name ppp authentication PAP|CHAP|MSCHAP
Replace group_name with the same group name you defined in the previous step. Enter the appropriate
keyword for the type of authentication used by your ISP:
PAP—Password Authentication Protocol
CHAP—Challenge Handshake Authentication Protocol
MS-CHAP—Microsoft Challenge Handshake Authentication Protocol
Note When using CHAP or MS-CHAP, the username may be referred to as the remote system name,
while the password may be referred to as the CHAP secret.
Vue de la page 164
1 2 ... 160 161 162 163 164 165 166 167 168 169 170 ... 465 466

Commentaires sur ces manuels

Pas de commentaire