H3C SR8800-F Configuration Manual page 285

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

[LNS] local-user vpdnuser class network
[LNS-luser-network-vpdnuser] password simple Hello
[LNS-luser-network-vpdnuser] service-type ppp
[LNS-luser-network-vpdnuser] quit
# Configure local authentication for PPP users in ISP domain system.
[LNS] domain system
[LNS-isp-system] authentication ppp local
[LNS-isp-system] quit
# Enable L2TP.
[LNS] l2tp enable
# Create a PPP address pool.
[LNS] ip pool aaa 192.168.0.10 192.168.0.20
[LNS] ip pool aaa gateway 192.168.0.1
# Create Virtual-Template 1, specify its PPP authentication mode as CHAP, and use address
pool aaa to assign IP addresses to the PPP users.
[LNS] interface virtual-template 1
[LNS-virtual-template1] ppp authentication-mode chap domain system
[LNS-virtual-template1] remote address pool aaa
[LNS-virtual-template1] quit
# Create L2TP group 1 in LNS mode.
[LNS] l2tp-group 1 mode lns
# Configure the local tunnel name as LNS.
[LNS-l2tp1] tunnel name LNS
# Specify Virtual-Template 1 for receiving calls from an LAC.
[LNS-l2tp1] allow l2tp virtual-template 1 remote LAC
# Enable tunnel authentication, and specify the tunnel authentication key as aabbcc.
[LNS-l2tp1] tunnel authentication
[LNS-l2tp1] tunnel password simple aabbcc
[LNS-l2tp1] quit
3.
On the remote system, enter vpdnuser as the username and Hello as the password in the
dial-up network window to dial a connection.
Verifying the configuration
# After the dial-up connection is established, use the display ppp access-user command on the
LNS to display the online user information.
[LNS] display ppp access-user user-type lns
Interface Username MAC address
BAS0
vpdnuser -
# After the dial-up connection is established, verify that the remote system can obtain an IP address
and can ping the private IP address of the LNS.
# On the LNS, use the display l2tp tunnel command to check the established L2TP tunnels.
[LNS] display l2tp tunnel
LocalTID RemoteTID State
196
3542
# On the LNS, use the display l2tp session command to check the established L2TP sessions.
[LNS] display l2tp session
LocalSID
2041
Established
RemoteSID
LocalTID
64
196
IP address
IPv6 address
192.168.0.10
-
Sessions RemoteAddress
1
1.1.2.1
State
Established
269
IPv6 PDPrefix
-
RemotePort RemoteName
1701
LAC

Advertisement

Table of Contents
loading

Table of Contents