OfficeConnect Remote ADSL Router CLI User’s Guide
Release
Part Number 10043337 AA
5400 Bayfront Plaza
3Com Corporation
Santa Clara, California
95052-8145
ACCESSING THE CONFIGURATION INTERFACE
Table of Contents
CLI COMMAND CONVENTIONS AND TERMINOLOGY
CONFIGURATION METHODS
MANUAL SETUP
QUICKVC SETUP
Starting QuickVC Setup
IPX Routing Network Service PPP
Setting Up a Virtual Private Network VPN Tunnel
Setting Date and Time Using Network Time Protocol NTP
Configuring IPX for Remote Site Connections
Providing TFTP Access
Monitoring the DHCP Relay
OFFICECONNECT REMOTE 812 SAMPLE CONFIGURATION
CLI COMMAND DESCRIPTION
disable securityoption snmp useraccess
list ip addresses
list access
list processes
list services B list snmp communities or list snmp trapcommunities B
set system
INPUT COUNTERS
TCP COUNTERS
TELNET
FCC CLASS B STATEMENT FCC DECLARATION OF CONFORMITY
3COM CORPORATION LIMITED WARRANTY FCC CLASS A VERIFICATION STATEMENT
POSITIONAL HELP B Command Completion B
Output Pause
Establishing Communications with the OfficeConnect Remote
ACCESSING THE CONFIGURATION 1 INTERFACE
IBM-PC Compatible Computers
Macintosh Computers
telnet ipaddress
UNIX-Based Computers
Command Structure
CLI COMMAND CONVENTIONS AND 2 TERMINOLOGY
add ip network is the command
Parameters
Abbreviation and
Command
Completion
Help
Conventions Command Language Terminology
Page
Quick Setup Instructions
CONFIGURATION METHODS
QuickVC Setup Instructions
3-2 CHAPTER 3 CONFIGURATION METHODS
Manual Setup Instructions
CLI Quick Setup Script
QUICK SETUP
Restoring the OfficeConnect Remote 812 to an Unconfigured State
ADSL Router Installation Guide
Quick Setup Script Instructions
Quick Setup Script
Do you want to continue Quick Setup?
Password Protection
Quick Setup Management Information
Quick Setup Identification Information
TELNET information
Quick Setup IP Information
4-4 CHAPTER 4 QUICK SETUP
Quick Setup IPX Information
Sample Identification Information
Quick Setup Bridge Information
Management Information
TELNET Management
Sample Output Display as Quick Setup Executes
Page
CLI QuickVC Setup Script
QUICKVC SETUP
Starting QuickVC Setup OCR-DSL quickvc
Network Service PPP
CLI QuickVC Setup Script
Service RFC
Service PPP
IPX Routing Network
Bridging
Information
Sample Identification
Sample Output Display
as Quick Setup Executes
Page
Configuration Overview
MANUAL SETUP
Remote Site
Remember to save your configuration using the save all command before
Management
memory
Configuring Network Service Information
set vc vc name networkservice ppp
set vc vc name networkservice pppoa
set vc vc name networkservice pppoe
Currently, the SVC capability is disabled in the OCR
set vc vc name dynamicipaddressing dhcpclient
set vc vc name atm categoryofservice unspecifed pcr cell rate
Setting Up a Virtual
set vc vc name atm categoryofservice constant pcr cell rate
when transmitting data to the remote site
On the Remote Private Network “Server” Side
VPN Tunneling Overview Before You Begin Initiating a VPN Tunnel
On the 812 ADSL Router “Client” Side
VPN Tunnel
disable tunnel command
Enabling and Disabling a
list tunnel Use this command to list the name and status of tunnels
To learn how to set up encryption using the CLI, see Configuring
Authentication and Encryption
Values
Encryption
Configuring Windows 2000 Server to Support CHAP Authentication
MICROSOFT56BIT NONE REQUIRED
Router to Support Encryption for L2TP Tunnels
aaa authentication login cisco local
Configuring a Cisco Router to Support Encryption for L2TP Tunnels
Value Name ProhibitIpSec
vpdn-group 1 accept-dialin protocol l2tp virtual-template
peer default ip address pool L2TP
terminate-from hostname OfficeConnect local name c7200
interface Ethernet1/2
RIP Configuration router rip ver network IP Pool for L2TP Tunnel
ppp authentication pap
Debug vpdn command
error
6-14 CHAPTER 6 MANUAL SETUP
IP Routing
enable ip RIP
enable ip forwarding
disable ip RIP
show ip routing settings
addressselection
negotiate
set vc vc name
The defaultrouteoption can only be enabled in one VC profile
Remote Site
6-18 CHAPTER 6 MANUAL SETUP
Configuring Static and Framed IP Routes
Address Translation
continues to run until a NAT port frees up
For a vc added using QuickVC, NAT is enabled by default
used
Use the following command to configure PAT in a vc profile
port 80, private port 80, and the private address of the LAN Server
6-22 CHAPTER 6 MANUAL SETUP
Intelligent PAT
Please also note the following
set vc vc name intelligentpatoption Enable/Disable
Enabling NAT
set vc vc name natoption nat
6-24 CHAPTER 6 MANUAL SETUP
Configuring NAT Static and Dynamic Mappings
list nat vc vc name port port
add nat dynamic vc vc name publicpoolstart ip address count number
list nat vc vc name addr
AND / OR
Remote
DHCP
Configuring the DHCP Mode
set dhcp server mask ip address
set dhcp server startaddress ip address endaddress ip address
set dhcp server lease seconds
set dhcp server router ip address
set dhcp mode relay
Configuring the DHCP
show dhcp server counters
list dhcp server leases
show dns settings
enable dns
timeout
set dns
IPX Routing
Access Lists
list dns servers
Configuring IPX for Remote Site Connections
Enabling IPX Routing Configuring IPX for the LAN
6-32 CHAPTER 6 MANUAL SETUP
add ipxroute vc vc name ipxnet ipx network address metric number
Configuring IPX Static and Framed Routes
delete ipx service name type hex number
Configuring IPX Static and Framed Services
add ipxservice vc vc name hops number
6-34 CHAPTER 6 MANUAL SETUP
Bridging
Configuring IPX RIP and SAP
set ipx network network name
set ipx network network name
Bridging IP Traffic
Configuring Bridging for the Remote Site Connections
Configuring Bridging for the LAN
6-36 CHAPTER 6 MANUAL SETUP
set bridge forwarddelay seconds
show ip settings
Advanced Bridging Options
set bridge agingtime seconds
Simultaneous Bridging and Routing
set vc vcname macrouting enable
set bridge firewall discardroutedprotocols
Setting Date and Time
Administration
System
set bridge firewall fwdunicastonly
set enable ntp
Network Time Protocol CLI Commands
set disable ntp
For example set date 01-JAN-1998
set secondaryserver ipnameoraddr
set timeout seconds
set pollinginterval seconds
set retransmissions number
NTP Servers clock.psu.edu
set system name name location location contact contact
show system
list users
delete user name
list tftp clients
Setting Password Protection
After logging in to the CLI, you can exit the CLI with the command
exit cli
Data Filtering Overview
OfficeConnect Remote 812 Filtering Capabilities
6-46 CHAPTER 6 MANUAL SETUP
Filter Classes The OCR 812 supports three filter classes
Command Line
Creating Filters Using
Creating Filters
Overview
Protocol Rules
IP 1 ACCEPT src-addr=xxx 2 ACCEPT dst-addr=yyy 999 DENY
The OR operation can be implemented by successive rules
LENGTH - The number of bytes in the packet to compare to the value
IP Source and Destination Port Filtering Using CLI
IP Source and Destination Network Filtering Using CLI
IP Protocol Filtering Using CLI
IP RIP Packet Filtering Using CLI
IPX Source and Destination Host Filtering Using CLI
IPX Source and Destination Network Filtering Using CLI
IPX Source and Destination Socket Number Filtering Using CLI
IPX SAP Packet Filtering Using CLI
IPX RIP Packet Filtering Using CLI
Bridge / Generic Filtering Using CLI
IPX 1 ACCEPT src-socket = 999 DENY
Creating Filter Files
Using CLI
memory
Assigning Filters
Interface Using CLI
Applying Filters Using
by entering the CLI command set interface eth1 filteraccess off
VC/Remote Site Filters
Filter List Using CLI
Using CLI
Managing Filters
VPN Tunnel
Removing a Filter from
an Interface Using CLI
VC/Remote Site Profile
Deleting a Packet Filter
6-60 CHAPTER 6 MANUAL SETUP
Sample Configuration
OFFICECONNECT REMOTE 812 SAMPLE A CONFIGURATION
OCR 812 features
Overview
Global Configuration
Configuring the
enable securityoption remoteuser administration
add user root password !root
add ipx network ipx address 10 frame ethernetii enable yes
add dns server * vc Internet enable dns
disable bridge spanningtree add bridge network bridge
set dhcp server dns1 192.168.200.254 dns2
set vc Internet defaultrouteoption enable enable vc Internet
set vc Internet sendname internet-user sendpassword 1a2b3c
set vc Internet iprouting listen
set vc corp-net iprouting both
set vc corp-net ipxaddress 0 ipxrouting all enable vc corp-net
Configuring the Sample Network A-5
Page
CLI Commands
CLI Command Description
add access
vcblknetbios
primaryaddress ipaddress secondaryaddress ipaddress vcname vcname
add framedroute vc name
add ip defaultroute
iproute ipaddress metric number
metric
add ip network networkname
address ipxaddress interface eth1 enabled yes
address ipnetaddress frame ETHERNETII SNAP LOOPBACK interface eth1
gateway gatewayaddr metric hopcount
type servicetype
add ipx service servicename
add ipx route ipxnetaddress
gateway ipxhostaddress metric metricnumber ticks ticknumber
type servicetype
ipxnet ipxaddress metric hopcount ticks ticknumber
add ipxservice vc name
add ipxroute vc name
servertype servertype socket socketnumber enabled YES data “string”
add network service servicename status
CLI Commands B-7
add networkservice CLIaccess servertype TELNETD socket
Add network service example
address ipaddress access RO RW
closeactiveconnections TRUE FALSE
ipnameoraddr
add snmp trapcommunity name
address ipaddress
add tunnel
add vc name
add user name
arp output outputfilename ipnameoraddr
enabled yes
delete pat tcp vc
delete ipx route ipxnetaddress delete ipx service servicename
vcname
type servicetype
publicpoolstart ipaddress
publicaddress ipaddress
tunnelname
entries
disable ip network
DISABLE
DIAL
bridge forwarding
interfacename interface settings command
disable snmp
authentication traps
output outputfile
networks
ENABLE
HANGUP
using list network services
interfacename
interfacename interface settings command
HISTORY
HELP
KILL
LIST
mgmt - unknown, but filtering information exists
Interface - eth1, DA1 or loopback
If Name - eth1, DA1 or loopback
CLI Commands B-19
Prot - LOCAL or RIP
trapcommunities not list access
More or CR
PAUSED COMMANDS
Continue printing
Quit
PING
timeout timeoutvalue
RENAME
RESOLVE
set command history numerical range idle timeout minutes
forwarddelay seconds
SAVE
set bridge
set dhcp relay server1
enabled YES NO
set dhcp relay server2
address IPaddress
set dhcp server
set dns cachesize number numberretries number timeout seconds
DNS1 IPaddress
DNS2 IPaddress
set interface interfacename
filteraccess ON OFF inputfilter filtername outputfilter filtername
routingprotocol NONE RIPV1 RIPV2
B-28 APPENDIX B CLI COMMAND DESCRIPTION
CLI Commands B-29
routerid routerid
rippacketsize number ripupdateinterval number
rip BOTH DISABLE LISTEN RESPONDONLY SEND ripagemultiplier number
sap BOTH DISABLE LISTEN RESPONDONLY SEND sapagemultiplier number
sapupdateinterval number
poolmembers number
set network service adminname
Sets parameters for configured network services
Sets parameters for dynamic IPX networks
Authentication Options
A VPN tunnel can only be configured for MSCHAPv1 by using the CLI
For in-depth information about CHAP and PAP, see RFC
NONE REQUIRED
address IPaddress access RO RW
MPPE Options
set system
transmitauthenticationname name
name “name”
location “location”
sessiontimeout seconds
password password
set user username
message “message”
defaultrouteoption enable disable
bridging enable disable
idletimeout seconds
ip enable disable
CLI Commands B-37
set vc vcname atm
categoryofservice Unspecified UBR Variable VBR
set number
pcr number
Sets ATM parameters for VCs
Errored seconds since last link down
Total time since system reboot hours, minutes, seconds
Total errored seconds in 15 minutes
Total errored seconds in previous 15 minutes
Fields
Base Aging Time - time to age out a known MAC address, default
History Depth Current Prompt OCR-DSL Local Prompt OCR-DSL
settings
SPECIFIC ERROR COUNTERS
show dns counters show dns settings show filter filtername
Problems with Name Server - internal server error
INPUT COUNTERS
ICMP COUNTERS
OUTPUT COUNTERS
show interface Displays
show interface interfacename counters
INPUT COUNTERS
OUTPUT COUNTERS
IP Dynamic Address Pool Begin - start of IP address range
Fragments Needing Reassembly - # of fragmented datagrams
IP Dynamic Address Pool Size - size of IP address range
settings
OUTPUT COUNTERS
show ipx counters show ipx network networkname counters
INPUT COUNTERS
counters
show ipx rip
settings
settings
Dynamic Address Pool Begin - starting IPX address
show ipx sap
settings
Default Gateway - default IPX router address
name settings
vcname settings
vcname counters
name counters
SETTINGS for PPP BUNDLE 1 COMPRESSION
SETTINGS for PPP BUNDLE
SETTINGS for PPP LINK 1
Operational Status - opened or not opened
INPUT COUNTERS
show snmp counters Displays many SNMP statistics
System Location - modify using set system
System Contact - modify using set system
System Descriptor - for example
OUTPUT COUNTERS
TCP COUNTERS
TCP SETTINGS
INPUT COUNTERS
OUTPUT COUNTERS
TELNET
Commands
VERIFY
verify filter
Command Features
CLI Exit Commands
B-58 APPENDIX B CLI COMMAND DESCRIPTION
Comments
INDEX
Server
Input and Output filters contrasted
Static Services
Passwords
Page
Page
Page
STANDARD WARRANTY SERVICE
3Com Corporation LIMITED WARRANTY
HARDWARE
SOFTWARE
FCC DECLARATION OF CONFORMITY
FCC CLASS B STATEMENT
The Interference Handbook
ModelDescription