Eine Methode, ein Netzwerkszugangsserver, ein Authentifizierungs-, Berechtigungs- und Abrechnungsserver, ein Computerprogram mit Proxyfunktion für Benutzer-Authentifizierung, Berechtigung und Abrechnungsmeldungen über einen Netzwerkszugangsserver

The invention relates to providing network access to separate virtual private network. It relates to a method for proxying user authentication-authorization-and-accounting messages via a network access server (NAS) and at least two separated virtual private networks (VPNs), wherein a first VPN has i...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: FOCANT, STEPHANE, VAN ACKERE, MICHEL
Format: Patent
Sprache:ger
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention relates to providing network access to separate virtual private network. It relates to a method for proxying user authentication-authorization-and-accounting messages via a network access server (NAS) and at least two separated virtual private networks (VPNs), wherein a first VPN has it's own first authentication-authorization-and-accounting server (AAA server), and a second VPN has it's own second AAA server, comprising the steps of: said NAS D2 invokes (2) said first AAA server D7 for a user authentication-authorization-and-accounting and when said first AAA server D7 is not responsible for the user authentication-authorization-and-accounting, said first AAA server D7 partly steers the NAS D2 operation and identifying a configuration for a responsible second AAA server D8, if this information is available and if no information is available, forcing said NAS D2 to select or identify a configuration for the responsible second AAA server D8 and said NAS D2 invokes said second AAA server D8, based on the said configuration, and this second AAA server D8 performs a real user authentication-authorization-and-accounting and a decisive steering of the NAS operation (5). Further it relates to a network access server, an authentication-authorization-and-accounting server, and computer software products for proxying user authentication-authorization-and-accounting messages via a network access server.