L2Tp Configuration; L2Tp Overview; Introduction - H3C SR6600 Configuration Manual

Layer 2 – wan configuration
Hide thumbs Also See for SR6600:
Table of Contents

Advertisement

4

L2TP Configuration

This chapter includes these sections:

L2TP Overview

L2TP Configuration Task List
Displaying and Maintaining L2TP
L2TP Configuration Examples
Troubleshooting L2TP
L2TP Overview
This section covers these topics:

Introduction

Basic Concepts of L2TP
L2TP Tunneling Modes and Tunnel Establishment Process
L2TP Features
Protocols and Standards
Introduction
A virtual private dial-up network (VPDN) is a virtual private network (VPN) that utilizes the
dial-up function of public networks such as ISDN or PSTN networks to provide access
services for enterprises, small Internet service providers (ISPs), and telecommuters.
VPDN provides an economical and effective, point-to-point way for remote users to
connect to their home LANs.
VPDN technology uses a tunneling protocol to build secure VPNs for enterprises across
public networks. Branch offices and traveling staff can remotely access the headquarters'
Intranet resources through a virtual tunnel over public networks. Other users on the public
networks are not permitted access.
A VPDN tunnel can be NAS-initiated or client-initiated:
NAS-initiated VPDN tunnel. The network access server (NAS) connects a user's PPP
connection to the corporate VPDN gateway through a VPDN tunneling protocol,
establishing a tunnel with the VPDN gateway. The tunneling is transparent to users. A
user only needs to perform login operation once to access the enterprise network,
which authenticates the user and assigns the user a private IP address, eliminating the
necessity of the user for a public address. This mode requires that the NAS support
VPDN and the authentication system support VPDN attributes.
Client-initiated VPDN tunnel. A user accesses the Internet first, and then establishes
a tunnel with the VPDN gateway through a piece of dedicated client software, such as
the L2TP client offered by Windows 2000. In this mode, a user can access the
enterprise network anytime from any place, without the involvement of any ISP.
4-67

Advertisement

Table of Contents
loading

Table of Contents