Marc Hyman wrote about it:
> The feature is in beta test. A "caller #" has been added to the > connection profile. When caller-id is being used a profile is selected > by matching the incoming phone number with the field in the profile. > A profile authenticated this way will *not* be re-authenticated using > PAP or CHAP. > > If a local profile is not found a RADIUS request will be made using > the phone number as the name with a magic password. An attribute is > passed to RADIUS with the request that is not passed with normal > authentication requests. This stops joe user from trying to > authenticate by guessing phone numbers.