Warning: mkdir() [
function.mkdir]: Permission denied in
/home/webs/affiliatelib2/CacheManager.php on line
12
Warning: mkdir() [
function.mkdir]: No such file or directory in
/home/webs/affiliatelib2/CacheManager.php on line
12
Warning: fopen(/home/templatecore2cache//*cluesnet.com/bb/bb5709ef6e0c3ba1c8587550d3c92a0f74c5d351.tc2cache) [
function.fopen]: failed to open stream: No such file or directory in
/home/webs/affiliatelib2/CacheManager.php on line
130
Warning: fwrite(): supplied argument is not a valid stream resource in
/home/webs/affiliatelib2/CacheManager.php on line
131
Warning: fclose(): supplied argument is not a valid stream resource in
/home/webs/affiliatelib2/CacheManager.php on line
132
Remote Authentication Dial In User Service (
RADIUS) is an AAA_protocol for applications such as network access or IP mobility. It is intended to work in both local and roaming situations.
Many networks services (including corporate networks and public
Internet service provider using modem, DSL, or wireless 802.11 technologies) require you to present security credentials (such as a username and
password or security certificate) in order to connect on to the network. Before access to the network is granted, this information is passed to a
Network Access Server (NAS) device over the link-layer protocol (for example,
Point-to-Point Protocol (PPP) in the case of many dialup or DSL providers), then to a RADIUS server over the RADIUS protocol. The RADIUS server checks that the information is correct using authentication schemes like
Password authentication protocol,
Challenge-handshake authentication protocol or Extensible Authentication Protocol. If accepted, the server will then indicate to the NAS that you are authorized to access the network. RADIUS also allows the authentication server to supply the NAS with additional parameters, such as
- The specific IP address to be assigned to the user
- The address pool from which the user's IP should be chosen
- The maximum length that the user may remain connected
- An access list, priority queue or other restrictions on a user's access
- L2TP parameters
The RADIUS protocol does not transmit passwords in cleartext between the NAS and RADIUS server (not even with PAP protocol), but in hidden, using a rather complex operation instead, which involves
MD5 hashing and shared secret, as described in references.
RADIUS is also commonly used for accounting purposes. The NAS can use RADIUS accounting packets to notify the RADIUS server of events such as
- The user's session start
- The user's session end
- Total packets transferred during the session
- Volume of data transferred during the session
- Reason for session ending
The primary purpose of this data is so that the user can be
Bill (payment) accordingly; the data is also commonly used for
statistical purposes and for general network monitoring.
Additionally RADIUS is widely used by
VoIP service providers. It is used to pass login credentials of a
Session Initiation Protocol end point (like a
broadband phone) to a
SIP Registrar using
digest authentication, and then to RADIUS server using RADIUS. Sometimes it is also used to collect call detail records (CDRs) later used, for instance, to bill customers for international long distance.
RADIUS was originally specified in an RFI by Merit Network in 1991 to control dial-in access to NSFnet. Livingston Enterprises responded to the RFI with a description of a RADIUS server. Merit Network awarded the contract to Livingston Enterprises that delivered their PortMaster series of Network Access Servers and the initial RADIUS server to Merit. RADIUS was later (
1997) published as RFC 2058 and RFC 2059 (current versions are RFC 2865 and RFC 2866). Now, several commercial and open-source RADIUS servers exist. Features can vary, but most can look up the users in text files, Lightweight Directory Access Protocol servers, various databases, etc. Accounting records can be written to text files, various databases, forwarded to external servers, etc. Simple Network Management Protocol is often used for remote monitoring. RADIUS proxy servers are used for centralized administration and can rewrite RADIUS packets on the fly (for security reasons, or to convert between vendor dialects).
RADIUS is a common authentication protocol utilized by the 802.1X security standard (often used in wireless networks). Although RADIUS was not initially intended to be a wireless security authentication method, it improves the
Wired Equivalent Privacy encryption key standard, in conjunction with other security methods such as
Extensible Authentication Protocol-
Protected Extensible Authentication Protocol.
RADIUS is extensible; many vendors of RADIUS hardware and software implement their own variants using Vendor-Specific Attributes (VSAs).
RADIUS is used by RSA Security SecurID to enable strong authentication for access control; products such as
PhoneFactor add two-factor authentication to legacy RADIUS applications that typically only support username and password authentication.
RADIUS uses UDP ports 1812 or 1645 for Authentication and 1813 or 1646 for Accounting. For example,
Microsoft RADIUS servers default to the higher ports but Cisco devices default to the lower ports. Juniper Networks' RADIUS servers also defaults to the lower ports. The official
IETF port number assignment is the higher port numbers 1812 and 1813.
The DIAMETER protocol is the planned replacement for RADIUS. DIAMETER uses Stream Control Transmission Protocol or
Transmission Control Protocol while RADIUS uses User Datagram Protocol as the transport layer.
Standards
The RADIUS protocol is currently defined in:
- RFC 2865 Remote Authentication Dial In User Service (RADIUS)
- RFC 2866 RADIUS Accounting
Other relevant RFCs are:
- RFC 2548 Microsoft Vendor-specific RADIUS Attributes
- RFC 2607 Proxy Chaining and Policy Implementation in Roaming
- RFC 2618 RADIUS Authentication Client MIB
- RFC 4668 RADIUS Authentication Client MIB for IPv6 (Supersedes: RFC 2618)
- RFC 2619 RADIUS Authentication Server MIB
- RFC 4669 RADIUS Authentication Server MIB for IPv6 (Supersedes: RFC 2619)
- RFC 2620 RADIUS Accounting Client MIB
- RFC 4670 RADIUS Accounting Client MIB for IPv6 (Supersedes: RFC 2620)
- RFC 2621 RADIUS Accounting Server MIB
- RFC 4671 RADIUS Accounting Server MIB for IPv6 (Supersedes: RFC 2621)
- RFC 2809 Implementation of L2TP Compulsory Tunneling via RADIUS
- RFC 2867 RADIUS Accounting Modifications for Tunnel Protocol Support
- RFC 2868 RADIUS Attributes for Tunnel Protocol Support
- RFC 2869 RADIUS Extensions
- RFC 2882 Network Access Servers Requirements: Extended RADIUS Practices
- RFC 3162 RADIUS and IPv6
- RFC 3575 IANA Considerations for RADIUS
- RFC 3576 Dynamic Authorization Extensions to RADIUS
- RFC 3579 RADIUS Support for EAP (Updates: RFC 2869)
- RFC 3580 IEEE 802.1X RADIUS Usage Guidelines
- RFC 4014 RADIUS Attributes Suboption for the DHCP Relay Agent Information Option
- RFC 4372 Chargeable User Identity
- RFC 4590 RADIUS Extension for Digest Authentication (new revision pending)
- RFC 4675 RADIUS Attributes for Virtual LAN and Priority Support
- RFC 4679 DSL Forum Vendor-Specific RADIUS Attributes
- RFC 4818 RADIUS Delegated-IPv6-Prefix Attribute
- RFC 4849 RADIUS Filter Rule Attribute
See Also
External links
- An Analysis of the RADIUS Authentication Protocol
- List of RADIUS attributes
- Configure RADIUS for secure 802.1x wireless LANs
- Self-sign a RADIUS server for secure PEAP or EAP-TTLS authentication
Radius - the religious drama society of Great Britain
The site for everyone interested in exploring the values of faith through drama and the performing arts
Radius - archive
Radius Publications Mar 2002 - Cell Talk and Iscariot Radius Library Library Catalogue 2001 - Additions to the library 2001 2000 - Additions to the ...
Radius - Wikipedia, the free encyclopedia
In classical geometry, a radius (plural: radii) of a circle or sphere is any line segment from its center to its perimeter. By extension, the radius of a circle or sphere is the ...
Radius (bone) - Wikipedia, the free encyclopedia
The radius is the bone of the forearm that extends from the lateral side of the elbow to the thumb side of the wrist. The radius is situated on the lateral side of the ulna, which ...
RADIUS from FOLDOC
RADIUS. Remote Authentication Dial-In User Service. Try this search on Wikipedia, OneLook, Google
Radius wireless remote control, SCADA, Telemetry, distribution ...
Radius Mission. To be a leading source of equipment and services for the global market in Wireless Communication, Utility Automation and Remote Control.
Definition: radius from Online Medical Dictionary
The Online Medical Dictionary is a searchable dictionary of definitions from medicine, science and technology.
Monitor Audio Radius
Radius ... CPC Radius Stereo View Product
Radius Consulting Ltd: Not just web design {Flash intro}
Radius Consulting for bespoke website design, maintenance, and the registratio of lost domain names.
Radius Computer Services
Since its formation in 1975, the Radius Group of companies has focused on the supply of complete business solutions in defined vertical markets.