Figure 10-8 L2Tp Tunnel Across The Internet; How The Max Creates L2Tp Tunnels - Lucent Technologies MAX 6000 Configuration Manual

Hide thumbs Also See for MAX 6000:
Table of Contents

Advertisement

Setting Up Virtual Private Networks
Configuring L2TP tunnels for dial-in clients
Figure 10-8. L2TP tunnel across the Internet
Dial-in
clients

How the MAX creates L2TP tunnels

The dial-in client, the LAC, and the LNS establish, use, and terminate an L2TP-tunnel
connection as follows:
1
2
3
4
5
6
7
LAC and LNS mode
The MAX unit can function as an LAC, an LNS, or both. L2TP supports multimode in which a
unit is both a LAC (foreign agent) and a LNS (home agent). As L2TP LNS, the unit terminates
the L2TP session and authenticates the user. If the user's profile on the LNS calls for an L2TP
tunnel, the LNS then switches that user's session. The unit acts as an L2TP LAC and originates
a new L2TP tunnel and session. The MAX unit operates as an LNS as far as the first LAC is
concerned, and as an LAC as far as the next hop is concerned.
Note: In L2TP switching, a MAX unit can be both a LNS and a LAC simultaneously for the
same session. The session arrives and is serviced by the unit acting as a LNS.
Tunnel authentication
You can configure the LNS to authenticate a tunnel during tunnel creation. You must enable
tunnel authentication on both the LAC and LNS.
On the LNS, you must create a Names/Passwords profile where:
10-32
P50
LAC
Modem
RADIUS server
A client dials, over either a modem or ISDN connection, into the LAC.
On the basis of dialed number or after authentication (depending on the LAC
configuration), the LAC communicates with the LNS to establish an IP connection.
Over the IP connection, the LAC and LNS establish a control channel.
The LAC sends an Inbound Call Request to the LNS.
Depending on the LNS configuration, the client might need to authenticate itself a second
time.
After successful authentication, the tunnel is established, and data traffic flows.
When the client disconnects from the LAC, the LAC sends a Call Disconnect Notify
message to the LNS. The LAC and LNS disconnect the tunnel.
The value in the Ethernet > Names/Passwords > Name parameter matches the value of the
System > Sys Config > Name parameter on the LAC.
LNS
Internet
L2TP tunnel
MAX 6000/3000 Network Configuration Guide
Private network

Advertisement

Table of Contents
loading

This manual is also suitable for:

Max 3000

Table of Contents