Configuring An Authentication Method; Configuring Keepalive Parameters - HPE FlexNetwork HSR6800 Configuration Manual

Comware 7 layer 3, ip services
Hide thumbs Also See for FlexNetwork HSR6800:
Table of Contents

Advertisement

Step
4.
Specify encryption
algorithms.

Configuring an authentication method

The VAM server uses the specified method to authenticate clients in the ADVPN domain. The VAM
server supports PAP and CHAP authentication.
If the specified ISP domain does not exist, the authentication will fail. A newly configured
authentication method does not affect registered VAM clients. It applies to subsequently registered
VAM clients.
To configure an authentication method:
Step
1.
Enter system view.
2.
Enter ADVPN domain view.
3.
Specify an authentication
method.

Configuring keepalive parameters

Keepalive parameters include a keepalive interval and a maximum number of keepalive retries. The
VAM server assigns the configured keepalive parameters to clients in the ADVPN domain.
A client sends keepalives to the server at the specified interval. If a client does not receive any
responses from the server after the maximum keepalive attempts (keepalive retries + 1), the client
stops sending keepalives. If the VAM server does not receive any keepalives from a client before the
timeout timer expires, the server removes information about the client and logs off the client. The
timeout time is the product of the keepalive interval and keepalive attempts.
Newly configured keepalive parameters do not affect registered VAM clients. They apply to
subsequently registered clients.
If a device configured with dynamic NAT exists between the VAM server and VAM clients, configure
the keepalive interval to be shorter than the aging time of NAT entries.
Configure proper values for the keepalive parameters depending on the network condition.
To configure keepalive parameters:
Step
1.
Enter system view.
2.
Enter ADVPN domain view.
Command
encryption-algorithm
{ 3des-cbc | aes-cbc-128 |
aes-cbc-192 | aes-cbc-256 |
aes-ctr-128 | aes-ctr-192 |
aes-ctr-256 | des-cbc | none } *
Command
system-view
vam server advpn-domain
domain-name [ id domain-id ]
authentication-method { none |
{ chap | pap } [ domain
isp-name ] }
Command
system-view
vam server advpn-domain
domain-name [ id domain-id ]
333
Remarks
The default encryption algorithms
are AES-CBC-256,
AES-CBC-192, AES-CBC-128,
AES-CTR-256, AES-CTR-192,
AES-CTR-128, 3DES-CBC, and
DES-CBC in descending order of
priority.
Remarks
N/A
N/A
By default, the authentication
method is CHAP, and the default
domain is used.
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents