Configuring Aaa Authentication On An Lns; Setting The Maximum Number Of Icrq Packets That The Lns Can Process Per Second; Configuring Optional L2Tp Parameters; Configuring L2Tp Tunnel Authentication - H3C SR8800-F Configuration Manual

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

Configuring AAA authentication on an LNS

After you configure AAA authentication on an LNS, the LNS can authenticate the usernames and
passwords of remote access users. If a user passes AAA authentication, the user can communicate
with the LNS to access the private network.
Configure AAA authentication on the LNS in one of the following cases:
LCP renegotiation is not configured in NAS-initiated mode.
The VT interface is configured with PPP user authentication and LCP renegotiation is
configured in NAS-initiated mode.
The VT interface is configured with PPP user authentication in client-initiated mode or
LAC-auto-initiated mode.
LNS side AAA configurations are similar to those on an LAC (see
an
LAC").
Setting the maximum number of ICRQ packets that the LNS
can process per second
To avoid device performance degradation and make sure the LNS can processes ICRQ requests
correctly, use this feature to adjust the ICRQ packet processing rate limit.
To set the maximum number of ICRQ packets that the LNS can process per second:
Step
1.
Enter system view.
2.
Set the maximum number of
ICRQ packets that the LNS
can process per second

Configuring optional L2TP parameters

The optional L2TP parameter configuration tasks apply to both LACs and LNSs.

Configuring L2TP tunnel authentication

Tunnel authentication allows the LAC and LNS to authenticate each other. Either the LAC or the LNS
can initiate a tunnel authentication request.
You can enable tunnel authentication on both sides or either side.
To ensure a successful tunnel establishment when tunnel authentication is enabled on both sides or
either side, set the same non-null key on the LAC and the LNS. To set the tunnel authentication key,
use the tunnel password command.
When neither side is enabled with tunnel authentication, the key settings of the LAC and the LNS do
not affect the tunnel establishment.
To ensure tunnel security, enable tunnel authentication.
For the tunnel authentication key change to take effect, change the tunnel authentication key before
tunnel negotiation is performed.
To configure L2TP tunnel authentication:
Command
system-view
l2tp icrq-limit number
264
"Configuring AAA authentication on
Remarks
N/A
By default, the maximum number
of ICRQ packets that the LNS can
process per second is not limited.

Advertisement

Table of Contents
loading

Table of Contents