Complex Networking; L2Tp Troubleshooting - H3C SecPath F1800-A Operation Manual

H3c secpath f1800-a firewall
Hide thumbs Also See for H3C SecPath F1800-A:
Table of Contents

Advertisement

Operation Manual - VPN
H3C SecPath F1800-A Firewall
# Set user authentication mode and accounting mode.
[SecPath] aaa
[SecPath-aaa] authentication-scheme my_auth
[SecPath-aaa-authen-my_auth] authentication-mode radius
[SecPath-aaa] accounting-scheme my_acct
[SecPath-aaa-accounting-my_acct] accounting-mode radius

2.4.3 Complex Networking

The SecPath F1800-A can serve as LAC and LNS at the same time, supporting
multiple users call in. L2TP can receive and originate multiple calls at the same time
as long as memory and line are unlimited. These complex networking requests and
configuration can be performed by referring to above cases.
Pay special attention to configuration of static routing as many applications are
originated by routing.

2.5 L2TP Troubleshooting

There are some common faults in establishing VPN connection. First, make sure both
LAC and LNS are on the public network and connected correctly.
Fault 1: Tunnel creation fails.
Troubleshooting:
Reasons are as follows:
LNS address is incorrectly set on LAC side.
No L2TP group is set to receive peer end in the tunnel on LNS. For details, refer
to the allow command.
Tunnel authentication is not passed. The passwords of both sides should be the
same if authentication is configured. With respect to L2TP in support of
multi-instance configuration, LNS uses the allow L2TP virtual-template
virtual-template-number remote remote-name [ domain remote-name ]
command to identify instances. The tunnel authentication passwords of each
L2TP group with same remote-name, different domain-name should be
consistent with LAC.
With respect to non-multi-instance, if local end is disconnected forcibly, while
peer end does not receive the Disconnect packet because of network
transmission or other reasons and originates a tunnel connection at the same
time, the request will fail because it needs a certain time for peer end to detect
the link has been disconnected. When L2TP multi-instance is disabled, the
tunnel connection request originated by two ends from the same IP address is
not allowed.
A router can serve as LAC and LNS for different tunnels at the same time. With
respect to L2TP in support of multi-instance configuration, tunnel creation will fail
7-31
Chapter 2 L2TP Configuration

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the H3C SecPath F1800-A and is the answer not in the manual?

Table of Contents