XAUTH with external RADIUS servers

As of LCOS version 7.60, LANCOM devices can identify and authenticate remote stations with the Extended Authentication Protocol (XAUTH). Authentication referred to the user data in the PPP list.

As of LCOS version 7.80, XAUTH authentication can also be handled by an (external) RADIUS server. For example, this allows reference to existing RAS user data on the RADIUS server, assuming that RADIUS-authenticated dial-in via PPP has been set up for VPN with XAUTH.

To supplement VPN dial-in with XAUTH for authentication, please proceed as follows:

  1. Set up a VPN dial-in account, for example with the LANconfig Setup Wizard.
  2. Activate XAUTH in the VPN client at the station which is to dial in. The user name and password are the same as those stored on the RADIUS server.




  1. Activate the authentication of dial-in remote stations via the XAUTH protocol on an external RADIUS server. In LANconfig, access the configuration area Communication and the RADIUS tab to activate the "Exclusive" operating mode for the RADIUS server. With this setting, all incoming XAUTH requests are authenticated by the RADIUS server.




  1. You should also specify the IP address, the port, and the key for the external RADIUS server.
  2. Also set PPP operation to "Exclusive" so that incoming XAUTH requests are authenticated by the RADIUS server only.