VPDN and L2TP Overview 605

Figure 182 Call setup flow of L2TP channel

RADIUS Server

RADIUS Server

 

 

 

 

 

Access request

 

 

 

 

(12)(16)

 

 

 

 

Access response

 

 

(12)

(13)

(13)(17)

 

 

 

(4) Request

(5) AV Pairs

 

 

 

tunnl message

Tunnel messae(

(16)

(17)

 

 

 

 

 

PC

PSTN/ISDN

 

WAN

 

 

PC

Router A

Router B

 

PC

LAC

LNS

 

(1)Call Setup

 

 

 

 

 

(2) PPP LCP Setup

(3) PAP or CHAP authentication

RADIUS Aut hent i cat i on

(6)Tunnel establishment

(7)SCCRQ message [ LAC challenge ]

(8)SCCRP message [ LNS CH AP response, CHAP challenge ]

(9)SCCCN message [ Authentication passes£LAC CHAP response ]

(10)Authentication passes)

(11)user CHAP response + response identifier + PPP negotiation parameters

RADIUS Aut hent i cat i on

14)Optional second time CHAP challenge(

(15)CHAP response

(18)Authentication passes

V.Features of L2TP

Flexible identity authentication mechanism and high security

L2TP protocol by itself does not provide connection security, but it can depend on the authentication (e.g. CHAP and PAP) provided by PPP, so it has all security features of PPP. L2TP can be integrated with IPSec to fulfill data security, so it is difficult to attack the data transmitted with L2TP. As required by specific network security, L2TP adopts channel encryption technique, end-to-end data encryption or application layer data encryption on it to improve data security.

Multi-protocol transmission

L2TP transmits PPP packets, so multiple protocols can be encapsulated in

PPPpackets.

Supports the authentication of RADIUS server

LAC requires the authentication of RADIUS with user name and password. RADIUS server receives authentication request of the user, fulfils the authentication and returns the configuration information to establish the connection to LAC.

Supports internal address allocation

LNS can be put behind the Intranet firewall. It can dynamically distribute and manage the addresses of remote users and support the application of private

Page 609
Image 609
3Com 10014299 manual Features of L2TP, Call setup flow of L2TP channel