
Chapter 3. Terminal Menu Operation and Structure
61200176L1-1 Express 6100/6120 User Manual 3-27
numberof attempts to communicatewith the primary server isequal to
theretrycount,thesecondaryserver(ifdefined) istried. If thesecondary
server does notrespond within the retry count, the PPPpeer (or Telnet
session) is not authenticated and is dropped. The default is 5.
»» Security/PPP
Write security:1; Readsecurity: 2
The PPP peer can be authenticated using three standard methods:
PAP (Password Authentication Protocol), CHAP (Challenge Hand-
shake Protocol) and EAP (Extensible Authentication Protocol). The
strengthoftheauthenticationisdetermined intheorderEAP,CHAP,
followed byPAP, whereEAPisthe strongestand PAPisthe weakest.
PAP is a clear-text protocol, which means it is sent over the PPP link
inareadableformat. Care mustbetaken nottoallow highlysensitive
passwords to become compromised using this method. CHAP and
EAP use a one-way hashing algorithm which makes it virtually im-
possibletodeterminethepassword. EAPhasothercapabilitieswhich
allow more flexibility than CHAP.
The following selections are possible:
»» Security/Filter Defines
The Express 6100/6120 can filter packetsbased on certain parameters
withinthepacket. Themethodusedbythe Express 6100/6120allows
the highest flexibility for defining filters and assigning them to a pro-
file. The filters are set up in two steps: (1) defining the packet types,
and (2) adding them to a list under the PPP profile or DLCI map. See
PAP, CHAP or
EAP (def)
TheExpress6100/6120willaskfor EAP during
thefirstPPPLCPnegotiationandallowthePPP
peer to negotiate down to CHAP or PAP.
CHAP or EAP TheExpress6100/6120willaskfor EAP during
thefirstPPPLCPnegotiationandallowthePPP
peer to negotiate down to CHAP but not PAP.
EAP The Express 6100/6120will only allow EAP tobe
negotiated.IfthePPPpeer isnotcapableofdoing
EAP,then the connection will not succeed.
Comentarios a estos manuales