local-user

 

 

 

Configure PPP 169

Table 197 Configure the local authenticates the peer in CHAP mode

 

 

 

 

 

Operation

Command

 

 

 

 

 

Enable CHAP authentication

ppp authentication-mode chap [

 

 

call-in ] [ scheme { default

 

 

name-list }]

 

 

 

 

 

Disable CHAP authentication

undo ppp

authentication-mode

 

 

 

 

 

Configure the name of the local

ppp chap

user username

 

 

 

 

 

Delete the configured name of the local

undo ppp

chap user

 

 

 

 

Add the username and password of the peer

local-user user password {

 

into the local user list

simple

cipher } password

 

 

 

 

bConfigure the requester of CHAP authentication

Perform the following configuration in the interface view, and use the command in the system view.

Table 198 Configure as the peer authenticates the local in CHAP mode

Operation

Command

 

 

Configure the name of the local

ppp chap user username

 

 

Delete the configured name of the local

undo ppp chap user

 

 

Configure the password of the local for

ppp chap password { simple

authentication in CHAP mode

cipher } password

 

 

Delete the password of the local during

undo ppp chap password

authentication in CHAP mode

 

 

 

Add the username and password of the peer

local-user user password {

into the local user list

simple cipher } password

 

 

Generally, when the router configures user list, it configures the command ppp chap user username and local-useruser password { simple cipher } password, to perform CHAP authentication. While configuring CHAP authentication, user of one end is the username of the other, and the password must be the same.

In some situation, if the router cannot configure user list then it needs to configure the command ppp chap password { simple cipher } password to perform CHAP authentication.

While configuring CHAP authentication, note the following:

If one side originates the CHAP, authenticator should add username and password for the requester in the local database (use local-usercommand), and should send its username to the requester (use ppp chap user command). The requester should also add username and password for the authenticator in its database (use local-usercommand), and send its username and password to the authenticator (use ppp chap user command).

If one side originates the CHAP, authenticator only needs to start CHAP authentication itself (use ppp authentication-mode chap command). The requester does not need to configure the command.

If both sides originate CHAP simultaneously, then each side is both authenticator and requester. At this time, both sides need to configure all the commands supporting the CHAP authentication.

3Configure AAA Authentication and Accounting Parameter of PPP

Page 173
Image 173
3Com 10014299 manual Configure the local authenticates the peer in Chap mode, User username, Cipher password