- Enterasys Security Router User's Guide

VPN Configuration Overview
XSR User’s Guide 14-25
Authentication, Authorization and Accounting Configuration
The XSR’s AAA implementation handles all authentication, authorization and accounting of users
(Remote Access) and peer gateways (Site-to-Site). The components include:
Usernames and passwords for authentication
Associated group name for authorization of network services
IP addressing, including:
Virtual addresses from a local IP pool
DNS (primary and secondary) for remote access clients
WINS (primary and secondary) for remote access clients
Encryption settings for PPTP remote access clients
AAA per interface (for clients), for PPP, and debugging
Configuration for standard RADIUS. In addition to all the necessary values for
communicating securely with a RADIUS server, the XSR permits specifying a backup RADIUS
server for authentication failover. Refer to the table below for supported attributes.
Table 14-2 XSR-Supported RADIUS Attributes
Authentication Accounting Vendor-Specific
User-Name (1) AcctStatusType(40) MSCHAPResponse(1)
UserPassword(2) AcctInputOctets(42) MSCHAPError(2
NASIPAddress(4) AcctOutputOctets(43) MSCHAPDomain(10)
FramedIPAddress(8) AcctSessionId(44) MSCHAPChallenge(11)
FramedIPNetmask(9) AcctSessionTime(46) MSCHAPMPPEKeys(12)
FramedMTU(12) AcctInputPackets(47) MPPESendKey(16)
ReplyMessage
(18) AcctOutputPackets(48) MPPEReceiveKey(17
Class(25) AcctTerminateCause(49) MSCHAP2Response(25)
State(24) MSCHAP2Success(26)
VendorSpecific(26)
NASIdentifier(32)
LoginLATGroup(36
NASPortType(61)
EAPMessage(79
MessageAuthenticator(80)