RE: ppp auth chap callin w/o hostname

From: steven.j.nelson@xxxxxx
Date: Fri Aug 09 2002 - 05:33:44 GMT-3


   
Erhan

Basically callin specifies that the router should not issue a challenge to
the remote box on "Dial Out", however when being dialed into the box will
issue a challenge, here is an eample :-

R1-(Callin)-----ISDN-------R2

When R1 dials R2 then R2 issues the chap challenge and under normal
circumstances R1 will also issue a challenge to invoke the 2 way handshake,
however because R1 has callin configured then it will skip it's challenge to
R2 and only respond to R1's initial challenge.

If R2 dials R1 however R1 will issue a challenge and so will R2 as it does
not have any callin parameters set, so the challenge and responses are seen
from both ends.

You can check this out using debug ppp auth chap, and you will see some "I"
and "O" instances in the output, these are either challenges "I" in or
challenges "O" out.

I have no idea about authorities ???

Hope it helps

Thanks

Steve

-----Original Message-----
From: Erhan Kurt [mailto:kurt@superonline.net]
Sent: 09 August 2002 09:15
To: Nelson,SJ,Steven,IVNH33 C; ccielab@groupstudy.com
Subject: RE: ppp auth chap callin w/o hostname

Thanks Steve, actually I worked it out as well.
So, you mean that it's not important to put username on the box callin.

Again, the same question: is it okay for authorities? :)

-----Original Message-----
From: steven.j.nelson@bt.com [mailto:steven.j.nelson@bt.com]
Sent: 09 Agustos 2002 Cuma 11:18
To: kurt@superonline.net; ccielab@groupstudy.com
Subject: RE: ppp auth chap callin w/o hostname

Erhan

If you are using callin then it deosn't matter if you state usename and
password, try it and use a debug ppp auth and you will se the output
"treating connection as callin" and you will only see one set of "I" and "O"
instances.

This means that only one side is authenticating. I can setup if you like and
send you the output.

Thanks

Steve

-----Original Message-----
From: Erhan Kurt [mailto:kurt@superonline.net]
Sent: 09 August 2002 09:05
To: Nelson,SJ,Steven,IVNH33 C; ccielab@groupstudy.com
Subject: RE: ppp auth chap callin w/o hostname

Hi Steve,

Yes it works by writing username in each box. But in callin, the thing
wanted is authentication on only one box. So, we should not write username
in the box having ppp auth chap callin.

The only solution I found is putting router's hostname and enable secret via
commands ppp chap host and pp chap pass.

-----Original Message-----
From: steven.j.nelson@bt.com [mailto:steven.j.nelson@bt.com]
Sent: 09 Agustos 2002 Cuma 11:02
To: kurt@superonline.net; ccielab@groupstudy.com
Subject: RE: ppp auth chap callin w/o hostname

Erhan

Just ppp auth chap under the BRI / Dialer and also out a global username and
password in each box and that should do it.

Thanks

Steve

-----Original Message-----
From: Erhan Kurt [mailto:kurt@superonline.net]
Sent: 09 August 2002 08:02
To: ccielab@groupstudy.com
Subject: ppp auth chap callin w/o hostname

Hi All,

When using ppp auth chap callin, but no alternate hostname is given; I could
not run w/o entering ppp chap host <router-own-hostname> and ppp chap pass
<router-own-enable>

is there anyone to run by entering only the line: ppp auth chap callin ?

Erhan

***************************************************************************
Bu e-posta mesaji ve ekleri sadece gonderildigi kisi veya kuruma ozeldir.
Eger dogru kisiye ulasmadigini dusunuyorsaniz, bu mesajin gizlenmesi,
yonlendirilmesi, kopyalanmasi veya herhangi bir sekilde kullanilmasi
yasaktir. Mesaj iceriginde bulunan fikir ve yorumlar, Superonline'a degil
sadece gondericiye aittir. Bu mesaj bilinen tum viruslere karsi test
edilmistir.

***************************************************************************
This e-mail and any files transmitted with it are confidential and intended
solely for the use of the individual or entity to whom they are addressed.
If you are not the intended recipient you are hereby notified that any
dissemination, forwarding, copying or use of any of the information is
prohibited. The opinions expressed in this message belong to sender alone.
There is no implied endorsement by SUPERONLINE. This e-mail has been scanned
for all known computer viruses.
***************************************************************************



This archive was generated by hypermail 2.1.4 : Sat Sep 07 2002 - 19:48:21 GMT-3