▀ How Proxy Mobile IP Works in a WiFi Network with Multiple Authentication
Step
Description
14
On receiving the second authentication IKE_AUTH Request, PDIF checks the configured second authentication methods.
The second authentication may be either EAP-MD5 (default) or EAP-GTC. The EAP methods may be either EAP-
Passthru or EAP-Terminated.
a. If the configured method is EAP-MD5, PDIF sends the IKE_AUTH Response with EAP payload including
challenge.b. If the configured method is EAP-GTC, PDIF sends the IKE_AUTH Response with EAP-GTC.c. MS
processes the IKE_AUTH Response:
If the MS supports EAP-MD5, and the received method is EAP-MD5, then the MS will take the challenge,
compute the response and send IKE_AUTH Request with EAP payload including Challenge and Response.
If the MS does not support EAP-MD5, but EAP-GTC, and the received method is EAP-MD5, the MS sends
legacy-Nak with EAP-GTC.
15(a)
PDIF receives the new IKE_AUTH Request from MS.
If the original method was EAP-MD5 and MD5 challenge and response is received, PDIF sends RADIUS Access Request
with corresponding attributes (Challenge, Challenge Response, NAI, IMSI etc.).
15(b)
If the original method was EAP-MD5 and legacy-Nak was received with GTC, the PDIF sends IKE_AUTH Response
with EAP-GTC.
16
PDIF receives Access Accept from RADIUS and sends IKE_AUTH Response with EAP success.
17
PDIF receives the final IKE_AUTH Request with AUTH payload.
18
PDIF checks the validity of the AUTH payload and initiates Proxy-MIP setup request to the Home Agent if
is enabled. The HA address may be received from the RADIUS server in the Access Accept (Step 16) or may
required
be locally configured. PDIF may also remember the HA address from the first authentication received in the final DEA
message.
19
If
proxy-mip-required
20
PDIF received proxy-MIP RRP and gets the IP address and DNS addresses.
21
PDIF sets up the IPSec tunnel with the home address. On receiving the IKE_AUTH Response MS also sets up the IPSec
tunnel using the received IP address. PDIF sends the IKE_AUTH Response back to MS by including the CP payload with
the IP address and optionally the DNS addresses. This completes the setup.
22
PDIF sends a RADIUS Accounting start message.
Important:
However, here they deviate because the MS does not support EAP-MD5 authentication, but EAP-GTC. In response to
the EAP-MD5 challenge, the MS instead responds with legacy-Nak with EAP-GTC. The diagram below picks up at this
point.
▄ Cisco ASR 5x00 Packet Data Network Gateway Administration Guide
452
is disabled, PDIF assigns the IP address from the local pool.
For Proxy-MIP call setup using PAP, the first 14 steps are the same as for CHAP authentication.
Proxy-Mobile IP
proxy-mip-