New in this release 13Nortel VPN Router Security — Servers, Authentication, and CertificatesRADIUS dynamic filteringYou can set up and manage policy filters in the Remote Authentication Dial-InUser Service (RADIUS) server. If you use a RADIUS server to authenticate users,the VPN Router can retrieve those policy filters from the server. IPsec usertunnels are dynamically filtered based on attributes returned from theauthenticating RADIUS server. The returned dynamic filters are then prependedto the groups filter to which the user is bound.For more information about RADIUS dynamic filtering, see “ConfiguringRADIUS dynamic filters” on page 51.CRL Retrieval SchedulingWith CRL Retrieval Scheduling, the Nortel VPN Router administrator canconfigure the time and day that a CRL request is sent to the CRL Server.The CRL process has disadvantages because it is run at the LDAP priority and it isvery CPU intensive. In environments with heavy volume traffic and very largeLDAP CRLs, the CRL process can cause timeouts and data drops. Theadministrator can use the CRL Update Specific Time to avoid these timeouts anddata drops.You can use the GUI or the CLI to configure CRL Retrieval Scheduling.For more information about CRL Retrieval Scheduling, see “Configuring CRLRetrieval Scheduling” on page 88.