DES-7200 Configuration Guide Chapter 2 RADIUS Configuration
2-1
2 RADIUS Configuration
2.1 Radius Overview
The Remote Authentication Dial-In User Service (Radius) is a distributed client/server system
that works with the AAA to perform authentication for the users who are attempting to make
connection and prevent unauthorized access. In the implementation of our product, the
RADIUS client runs on the router or the network access server (NAS) to send the
authentication requests to the central RADIUS server. The central center includes all
information of user authentication and network services.
Since the RADIUS is a completely-open protocol, it has become a component and been
installed in such systems as UNIX and WINDOWS 2000, so it is the security server most
widely used for the time being.
The running process of the RADIUS is as follows:
z Prompt the user to enter username and password.
z The username and the encrypted password are sent to the RADIUS server via the
network.
z The RADIUS returns one of the following responses:
z The user authentication passes.
z The user authentication fails and it prompts to reenter the username and password.
z The RADIUS server sends the challenge request to gather more authentication
information from the user.
z The user authorization information is included in the ACCEPT response.
Here is a typical RADIUS topology: