The invention discloses a method and a device for enabling a
third generation (3G) user to safely access to network. When a
link control protocol (LCP) attribute and a user name of a
client, which are acquired by layer 2
tunneling protocol network
server (LNS), are acceptable, an temporary
internet protocol (IP) address is selected from an established temporary
IP address pool and distributed to the
client, fixed information which is sent by the
client and can verify the client identity is received, when the fixed information is received, the fixed information is correspondingly recorded with the user name and a
password, the point-to-point protocol (PPP) connection with the client is disconnected to trigger the client to initiate a second time virtual private dial-up network (VPDN) call, the client is informed of the specified
IP address which is distributed by
authentication,
authorization and accounting (AAA)
server to the client according to the recorded fixed information, the user name and the
password, or when the fixed information is received, the fixed information, the user name and the
password are directly sent to the AAA
server to verify the client, and after the client passes the
authentication, the client is informed of the specified
IP address which is distributed by the AAA server to the client. By means of the method and the device, the client can access to network only when the client is subjected to safety
authentication by the LNS, and the safety of network access is improved.