¨Client/Server model
–NAS operates as a RADIUS client by passing user info to RADIUS server and acting on response from server
–RADIUS server receives connection requests, authenticates user, and provides configuration settings to client
–RADIUS server can act as a proxy client to other authentication servers
¨Flexible authentication mechanisms
–Can support PPP PAP or CHAP, Unix login, and other authentication mechanisms
¨Extensible
–All transactions con attribute/value tuples
–New attributes can be added to existing protocol