User's Manual Part 2
December 20, 2004 SCP-LPS20x-011-012-01H
ADC Telecommunications, Inc. 129
PROFILE NAME PARAMETER
Specify the name to identify the profile.
SETTING PARAMETERS
Authentication Port
Specify the port to use for authentication. By default, RADIUS servers use port 1812.
Accounting Port
Specify the port to use for accounting. By default, RADIUS servers use port 1813.
Retry Interval
Controls the retry interval (in seconds) for access and accounting requests that time-out. If no reply is received
within this interval, the LPS-20x switches between the primary and secondary RADIUS servers (if defined). If a reply
is received after the interval expires, it is ignored. This parameter applies to access and accounting requests
generated by the following:
• administrator logins to the management tool
• customer logins via HTML
• MAC-based authentication of devices
• authentication of the LPS-20x
The maximum number of retries can be determined as follows:
• HTML-based Logins: The number of retries is calculated by taking the setting for HTML-based logins
Authentication Timeout parameter and dividing it by the value of this parameter. The default settings
result in
four retries (40/10).
• MAC-based and LPS-20x authentication: Number of retries is infinite.
• 802.1x authentication: Retries are controlled by the 802.1x client software.
Authentication Method
Choose the default authentication method the LPS-20x will use when exchanging authentication packets with the
primary/secondary RADIUS server defined for this profile.
For 802.1x users, the authentication method is always determined by the 802.1x client software and is not controlled
by the setting.
If traffic between the LPS-20x and the RADIUS server is not protected by a VPN, it is recommended that you use
EAP-MD5 or MSCHAP V2 if supported by your RADIUS server. (PAP, MSCHAP V1 and CHAP are less secure
protocols.)
NAS Id
Specify the network access server ID you want to use for the LPS-20x. By default, the serial number of the LPS-20x
is used. The LPS-20x includes the NAS-ID attribute in all packets that it sends to the RADIUS server.