AllExperts > Encyclopedia 
Search      
Find out about volunteering to AllExperts

RADIUS: Encyclopedia BETA


Free Encyclopedia
 Home · Index · Browse A-Z  · Questions and Answers ·
Encyclopedia

Browse A-Z
ABCDEFGHIJKLMNOPQRSTUVWXYZNum


License
Disclaimer

 
 
 
 
Free Online Courses
12 Weeks to Weight Loss
Take Charge of Stress
Learn How to Bake
Budgeting 101
Deeper Faith
DIY Fashion Makeover

       MORE E-COURSES
 
   

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z  Misc

RADIUS



Remote Authentication Dial In User Service (RADIUS) is an AAA (authentication, authorization and accounting) protocol for applications such as network access or IP mobility. It is intended to work in both local and roaming situations.

When you connect to an ISP using a modem, DSL, cable or wireless connection, for some providers, you must enter your username and password. This information is passed to a Network Access Server (NAS) device over the Point-to-Point Protocol (PPP), then to a RADIUS server over the RADIUS protocol. The RADIUS server checks that the information is correct using authentication schemes like PAP, CHAP or EAP. If accepted, the server will then authorize access to the ISP system and select an IP address, L2TP parameters, etc.

The RADIUS server will also be notified if and when the session starts and stops, so that the user can be billed accordingly; or the data can be used for statistical purposes.

Additionally RADIUS is widely used by VoIP service providers. It is used to pass login credentials of a SIP end point (like a broadband phone) to a SIP Registrar using digest authentication, and then to RADIUS server using RADIUS. Sometimes it is also used to collect call detail records (CDRs) later used, for instance, to bill customers for international long distance.

RADIUS was originally developed by Livingston Enterprises for their PortMaster series of Network Access Servers, but later (1997) published as RFC 2058 and RFC 2059 (current versions are RFC 2865 and RFC 2866). Now, several commercial and open-source RADIUS servers exist. Features can vary, but most can look up the users in text files, LDAP servers, various databases, etc. Accounting tickets can be written to text files, various databases, forwarded to external servers, etc. SNMP is often used for remote monitoring. RADIUS proxy servers are used for centralized administration and can rewrite RADIUS packets on the fly (for security reasons, or to convert between vendor dialects).

RADIUS is a common authentication protocol utilized by the 802.1x security standard (often used in wireless networks). Although RADIUS was not initially intended to be a wireless security authentication method, it improves the WEP encryption key standard, in conjunction with other security methods such as EAP-PEAP.

RADIUS is extensible; most vendors of RADIUS hardware and software implement their own dialects.

The DIAMETER protocol is the planned replacement for RADIUS. DIAMETER uses TCP while RADIUS uses UDP as the transport layer.

Standards

The RADIUS protocol is currently defined in:
*RFC 2865 Remote Authentication Dial In User Service (RADIUS)
*RFC 2866 RADIUS Accounting

Other relevant RFCs are:
* RFC 2548 Microsoft Vendor-specific RADIUS Attributes
* RFC 2607 Proxy Chaining and Policy Implementation in Roaming
* RFC 2618 RADIUS Authentication Client MIB
* RFC 2619 RADIUS Authentication Server MIB
* RFC 2620 RADIUS Accounting Client MIB
* RFC 2621 RADIUS Accounting Server MIB
* RFC 2809 Implementation of L2TP Compulsory Tunneling via RADIUS
* RFC 2867 RADIUS Accounting Modifications for Tunnel Protocol Support
* RFC 2868 RADIUS Attributes for Tunnel Protocol Support
* RFC 2869 RADIUS Extensions
* RFC 2882 Network Access Servers Requirements: Extended RADIUS Practices
* RFC 3162 RADIUS and IPv6
* RFC 3575 IANA Considerations for RADIUS
* RFC 3576 Dynamic Authorization Extensions to RADIUS
* RFC 3579 RADIUS Support for EAP
* RFC 3580 IEEE 802.1X RADIUS Usage Guidelines
* RFC 4014 RADIUS Attributes Suboption for the DHCP Relay Agent Information Option

See also

* DIAMETER
* FreeRADIUS
* Kerberos
* TACACS
* TACACS+
* List of RADIUS Servers

External links

* An Analysis of the RADIUS Authentication Protocol
* List of RADIUS attributes
* The Beginnings and History of RADIUS by John Vollbrecht



Email this page
About Us | Advertise on This Site | User Agreement | Privacy Policy | Kids' Privacy Policy | Help
About and About.com are registered trademarks of About, Inc. The About logo is a trademark of About, Inc. All rights reserved.
This is the "GNU Free Documentation License" reference article from the English Wikipedia. All text is available under the terms of the GNU Free Documentation License. See also our Disclaimer.