F-3
Cisco Secure ACS 3.0 for Windows 2000/NT Servers User Guide
78-13751-01, Version 3.0
AppendixF Cisco Secure ACS and Virtual Private Dial-up Networks VPDN Process
Figure F-3 Authorization of Domain Fails
If the ACS authorizes the domain, it returns the Tunnel ID and the IP address
of the home gateway (HG); these are used to create the tunnel. See
Figure F-4.
Figure F-4 ACS Authorizes Domain
4. The HG uses its ACS to authenticate the tunnel, where the username is the
name of the tunnel (nas_tun). See Figure F-5 on page F-4.
S6655
Corporation
VPDN user
User = mary@corporation.us
ACS
RSP
ACS
Authorization
failed
S6647
Corporation
VPDN user
User = mary@corporation.us
ACS
RSP
Authorization reply
Tunnel ID = nas_tun
IP address = 10.1.1.1
ACS
CHAP challenge