E-3
User Guide for Cisco Secure ACS for Windows Server
78-16592-01
Appendix E VPDN Processing
VPDN Process
Figure E-3 Authorization of Domain Fails
If the ACS authorizes the domain, it returns the Tunnel ID and the IP address
of the home gateway (HG); these are used to create the tunnel. See
Figure E-4.
Figure E-4 ACS Authorizes Domain
4. The HG uses its ACS to authenticate the tunnel, where the username is the
name of the tunnel (nas_tun). See Figure E-5.
S6655
Corporation
VPDN user
User = mary@corporation.us
ACS
RSP
ACS
Authorization
failed
S6647
Corporation
VPDN user
User = mary@corporation.us
ACS
RSP
Authorization reply
Tunnel ID = nas_tun
IP address = 10.1.1.1
ACS
CHAP challenge