Title: VCN Authentication
1Scenario 1
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Guest LAN (authentication required)
2Scenario 2
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Guest LAN (authentication required)
3Scenario 3
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Guest LAN (authentication required)
Employee LAN (no authentication required)
Terminal
4Scenario 4
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Employee LAN (no authentication required)
Workstation
5Scenario 4x
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Employee LAN (no authentication required)
More Workstation PCs
Workstation
6Scenario 5
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Guest LAN (authentication required)
Employee LAN (no authentication required)
Terminal
7Scenario 6
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Employee LAN (no authentication required)
Workstation
8Scenario 6x
WLAN (authentication required)
VCN Authentication (RADIUS-based)
Internet
Employee LAN (no authentication required)
More Workstation PCs
Workstation
9New VCN Network Infrastructure
- DD-WRTs Chillispot redirect the user to the VCN
hotspot login page (go to step 2). - (i) Registered VCN (hotspot or dial-up) users
can log in to the hotspot using their username
and password (go to step 3) (ii) Unregistered
users can register for a new hotspot account (go
to step 5). - The FreeRadius Server will do a look up on the
username to see whether the user is a first-time
hotspot user. (i) If the VCN user never use the
hotspot before, the server will acts as a proxy
and redirects the users info to the VCN Radius
Server for authentication (go to step 4) (ii) If
the VCN user has used the VCN hotspot service
before in which it means the HotSpot has
registered a hotspot account in its local
database (go to step 5). - The VCN Radius Server will authenticate the user
using his/her registered account in the data for
dial-up user. Once authentication is successful,
it will pass an acceptance back to the FreeRadius
Server (go to step 5). - The FreeRadius will either register an account if
it doesnt exist or update the accounting info on
the account and the user will be allowed to
access the site page and the internet
immediately.
4
1
DD-WRT-Powered AP
Database (Dialup-user)
3
5
Database (Hotspot-user)
VCN HotSpot Login Page
2