UMN:CLI
User Manual
V5824G
502
11.2.18
ONU Authentication from RADIUS Server
You can use the RADIUS authentication process when an ONU (ONT) is activated and it
attempts to access an OLT. The RADIUS Access-Request message is sent from the OLT
to the RADIUS server. If the ONU is valid, the RADIUS server consults a database of
ONUs to find the ONU which matches the authentication attributes in the connection
request. If the RADIUS server has the valid ONU-related information, it sends the
configuration settings placed into a RADIUS Access-Accept message to the OLT for the
ONU registration. The OLT receives the service profile settings from the RADIUS server
and it assigns a new service profile to ONU.
RADIUS Authentication Process
①
Upload MIB Info
: During the initial connection between OLT and ONU, the ONU
uploads the MIB information. On the OLT side, the OLT checks the ONU validation
using ONU model name, firmware version and serial number.
②
Sends RADIUS message
: If the RADIUS authentication is required when the OLT
and ONU are connected each other, the OLT sends Access-Request message with
the authentication attributes (user name, user password, OLT-ID, ONU-ID, ONT
model name, serial number, firmware version) to the RADIUS server.
③
Receive Response message
: If the RADIUS message is sent by a valid ONU, and if
the authentication attributes contain the correct values, the Access-Accept message
of ONU configuration settings is sent by the RADIUS server.
④
Set the configuration
: The OLT receives the service profile information from the
RADIUS server. The new service profile settings are assigned to ONU.
The RADIUS server sends Disconnect messages (DM) request in order to terminate a
user session on a network access server, whereas it sends Change-of-Authorization
(CoA) request messages to modify session authorization attributes of ONU.
The OLT checks that the key of DM message from the RADIUS server is valid. If the key
value is invalid, the packets are silently discarded.