Configuring The Source Ip Address Of L2Tp Tunnel Packets; Enabling Transferring Avp Data In Hidden Mode; Configuring Aaa Authentication On An Lac - HP MSR Router Series Wan Access Configuration Manual

Hide thumbs Also See for MSR Router Series:
Table of Contents

Advertisement

Step
2.
Enter L2TP group view in LAC
mode.
3.
Specify LNS IP addresses.

Configuring the source IP address of L2TP tunnel packets

For high availability, HP recommends using the IP address of a loopback interface as the source IP
address of L2TP tunnel packets on the LAC.
To configure the source IP address of L2TP tunnel packets:
Step
1.
Enter system view.
2.
Enter L2TP group view in LAC
mode.
3.
Configure the source IP
address of L2TP tunnel
packets.

Enabling transferring AVP data in hidden mode

L2TP uses Attribute Value Pairs (AVPs) to transmit tunnel negotiation parameters, session negotiation
parameters, and user authentication information. Transferring AVP data in hidden mode can hide
sensitive AVP data such as user passwords. This feature encrypts AVP data with the key configured by
using the tunnel password command before transmission.
This configuration takes effect only when the tunnel authentication feature is enabled. For more
information about configuring tunnel authentication, see
To enable transferring AVP data in hidden mode:
Step
1.
Enter system view.
2.
Enter L2TP group view in LAC
mode.
3.
Enable transferring AVP data
in hidden mode.

Configuring AAA authentication on an LAC

You can configure AAA authentication an LAC to authenticate the remote dialup users and initiate a
tunneling request only for qualified users. A tunnel will not be established for unqualified users.
The device supports both local AAA authentication and remote AAA authentication.
Command
l2tp-group group-number [ mode
lac ]
lns-ip { ip-address }&<1-5>
Command
system-view
l2tp-group group-number [ mode
lac ]
source-ip ip-address
"Configuring L2TP tunnel
Command
system-view
l2tp-group group-number [ mode
lac ]
tunnel avp-hidden
80
Remarks
N/A
By default, no LNS IP addresses
are specified.
Remarks
N/A
N/A
By default, the source IP address of
L2TP tunnel packets is the IP
address of the egress interface.
authentication."
Remarks
N/A
N/A
By default, AVP data is transferred
in plain text.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents