Part Number 10043337 AA
Release
OfficeConnect Remote ADSL Router CLI User’s Guide
95052-8145
3Com Corporation
5400 Bayfront Plaza
Santa Clara, California
CONFIGURATION METHODS
Table of Contents
ACCESSING THE CONFIGURATION INTERFACE
CLI COMMAND CONVENTIONS AND TERMINOLOGY
IPX Routing Network Service PPP
QUICKVC SETUP
MANUAL SETUP
Starting QuickVC Setup
Setting Up a Virtual Private Network VPN Tunnel
Monitoring the DHCP Relay
Configuring IPX for Remote Site Connections
Setting Date and Time Using Network Time Protocol NTP
Providing TFTP Access
OFFICECONNECT REMOTE 812 SAMPLE CONFIGURATION
CLI COMMAND DESCRIPTION
disable securityoption snmp useraccess
list processes
list access
list ip addresses
list services B list snmp communities or list snmp trapcommunities B
set system
TELNET
TCP COUNTERS
INPUT COUNTERS
Output Pause
3COM CORPORATION LIMITED WARRANTY FCC CLASS A VERIFICATION STATEMENT
FCC CLASS B STATEMENT FCC DECLARATION OF CONFORMITY
POSITIONAL HELP B Command Completion B
Macintosh Computers
ACCESSING THE CONFIGURATION 1 INTERFACE
Establishing Communications with the OfficeConnect Remote
IBM-PC Compatible Computers
telnet ipaddress
UNIX-Based Computers
Parameters
CLI COMMAND CONVENTIONS AND 2 TERMINOLOGY
Command Structure
add ip network is the command
Help
Command
Abbreviation and
Completion
Conventions Command Language Terminology
Page
QuickVC Setup Instructions
CONFIGURATION METHODS
Quick Setup Instructions
3-2 CHAPTER 3 CONFIGURATION METHODS
Manual Setup Instructions
ADSL Router Installation Guide
QUICK SETUP
CLI Quick Setup Script
Restoring the OfficeConnect Remote 812 to an Unconfigured State
Password Protection
Quick Setup Script
Quick Setup Script Instructions
Do you want to continue Quick Setup?
Quick Setup Management Information
Quick Setup Identification Information
4-4 CHAPTER 4 QUICK SETUP
Quick Setup IP Information
TELNET information
Quick Setup IPX Information
TELNET Management
Quick Setup Bridge Information
Sample Identification Information
Management Information
Sample Output Display as Quick Setup Executes
Page
Starting QuickVC Setup OCR-DSL quickvc
QUICKVC SETUP
CLI QuickVC Setup Script
Network Service PPP
CLI QuickVC Setup Script
Bridging
Service PPP
Service RFC
IPX Routing Network
as Quick Setup Executes
Sample Identification
Information
Sample Output Display
Page
Configuration Overview
MANUAL SETUP
memory
Remember to save your configuration using the save all command before
Remote Site
Management
Configuring Network Service Information
set vc vc name networkservice ppp
set vc vc name dynamicipaddressing dhcpclient
set vc vc name networkservice pppoe
set vc vc name networkservice pppoa
Currently, the SVC capability is disabled in the OCR
when transmitting data to the remote site
Setting Up a Virtual
set vc vc name atm categoryofservice unspecifed pcr cell rate
set vc vc name atm categoryofservice constant pcr cell rate
On the 812 ADSL Router “Client” Side
VPN Tunneling Overview Before You Begin Initiating a VPN Tunnel
On the Remote Private Network “Server” Side
Enabling and Disabling a
disable tunnel command
VPN Tunnel
list tunnel Use this command to list the name and status of tunnels
Values
Authentication and Encryption
To learn how to set up encryption using the CLI, see Configuring
Router to Support Encryption for L2TP Tunnels
Configuring Windows 2000 Server to Support CHAP Authentication
Encryption
MICROSOFT56BIT NONE REQUIRED
Value Name ProhibitIpSec
Configuring a Cisco Router to Support Encryption for L2TP Tunnels
aaa authentication login cisco local
interface Ethernet1/2
peer default ip address pool L2TP
vpdn-group 1 accept-dialin protocol l2tp virtual-template
terminate-from hostname OfficeConnect local name c7200
error
ppp authentication pap
RIP Configuration router rip ver network IP Pool for L2TP Tunnel
Debug vpdn command
6-14 CHAPTER 6 MANUAL SETUP
IP Routing
show ip routing settings
enable ip forwarding
enable ip RIP
disable ip RIP
addressselection
negotiate
Remote Site
The defaultrouteoption can only be enabled in one VC profile
set vc vc name
6-18 CHAPTER 6 MANUAL SETUP
Configuring Static and Framed IP Routes
Address Translation
used
For a vc added using QuickVC, NAT is enabled by default
continues to run until a NAT port frees up
Use the following command to configure PAT in a vc profile
port 80, private port 80, and the private address of the LAN Server
6-22 CHAPTER 6 MANUAL SETUP
Intelligent PAT
set vc vc name natoption nat
set vc vc name intelligentpatoption Enable/Disable
Please also note the following
Enabling NAT
6-24 CHAPTER 6 MANUAL SETUP
Configuring NAT Static and Dynamic Mappings
AND / OR
add nat dynamic vc vc name publicpoolstart ip address count number
list nat vc vc name port port
list nat vc vc name addr
Remote
DHCP
Configuring the DHCP Mode
set dhcp server router ip address
set dhcp server startaddress ip address endaddress ip address
set dhcp server mask ip address
set dhcp server lease seconds
list dhcp server leases
Configuring the DHCP
set dhcp mode relay
show dhcp server counters
set dns
enable dns
show dns settings
timeout
list dns servers
Access Lists
IPX Routing
6-32 CHAPTER 6 MANUAL SETUP
Enabling IPX Routing Configuring IPX for the LAN
Configuring IPX for Remote Site Connections
add ipxroute vc vc name ipxnet ipx network address metric number
Configuring IPX Static and Framed Routes
6-34 CHAPTER 6 MANUAL SETUP
Configuring IPX Static and Framed Services
delete ipx service name type hex number
add ipxservice vc vc name hops number
set ipx network network name
Configuring IPX RIP and SAP
Bridging
set ipx network network name
6-36 CHAPTER 6 MANUAL SETUP
Configuring Bridging for the Remote Site Connections
Bridging IP Traffic
Configuring Bridging for the LAN
set bridge agingtime seconds
show ip settings
set bridge forwarddelay seconds
Advanced Bridging Options
set bridge firewall discardroutedprotocols
set vc vcname macrouting enable
Simultaneous Bridging and Routing
set bridge firewall fwdunicastonly
Administration
Setting Date and Time
System
For example set date 01-JAN-1998
Network Time Protocol CLI Commands
set enable ntp
set disable ntp
set retransmissions number
set timeout seconds
set secondaryserver ipnameoraddr
set pollinginterval seconds
NTP Servers clock.psu.edu
delete user name
show system
set system name name location location contact contact
list users
list tftp clients
Setting Password Protection
After logging in to the CLI, you can exit the CLI with the command
exit cli
6-46 CHAPTER 6 MANUAL SETUP
OfficeConnect Remote 812 Filtering Capabilities
Data Filtering Overview
Filter Classes The OCR 812 supports three filter classes
Overview
Creating Filters Using
Command Line
Creating Filters
Protocol Rules
IP 1 ACCEPT src-addr=xxx 2 ACCEPT dst-addr=yyy 999 DENY
The OR operation can be implemented by successive rules
LENGTH - The number of bytes in the packet to compare to the value
IP RIP Packet Filtering Using CLI
IP Source and Destination Network Filtering Using CLI
IP Source and Destination Port Filtering Using CLI
IP Protocol Filtering Using CLI
IPX Source and Destination Socket Number Filtering Using CLI
IPX Source and Destination Network Filtering Using CLI
IPX Source and Destination Host Filtering Using CLI
IPX 1 ACCEPT src-socket = 999 DENY
IPX RIP Packet Filtering Using CLI
IPX SAP Packet Filtering Using CLI
Bridge / Generic Filtering Using CLI
memory
Using CLI
Creating Filter Files
Assigning Filters
VC/Remote Site Filters
Applying Filters Using
Interface Using CLI
by entering the CLI command set interface eth1 filteraccess off
VPN Tunnel
Using CLI
Filter List Using CLI
Managing Filters
Deleting a Packet Filter
an Interface Using CLI
Removing a Filter from
VC/Remote Site Profile
6-60 CHAPTER 6 MANUAL SETUP
Overview
OFFICECONNECT REMOTE 812 SAMPLE A CONFIGURATION
Sample Configuration
OCR 812 features
add user root password !root
Configuring the
Global Configuration
enable securityoption remoteuser administration
set dhcp server dns1 192.168.200.254 dns2
add dns server * vc Internet enable dns
add ipx network ipx address 10 frame ethernetii enable yes
disable bridge spanningtree add bridge network bridge
set vc Internet iprouting listen
set vc Internet sendname internet-user sendpassword 1a2b3c
set vc Internet defaultrouteoption enable enable vc Internet
Configuring the Sample Network A-5
set vc corp-net ipxaddress 0 ipxrouting all enable vc corp-net
set vc corp-net iprouting both
Page
vcblknetbios
CLI Command Description
CLI Commands
add access
primaryaddress ipaddress secondaryaddress ipaddress vcname vcname
metric
add ip defaultroute
add framedroute vc name
iproute ipaddress metric number
gateway gatewayaddr metric hopcount
address ipxaddress interface eth1 enabled yes
add ip network networkname
address ipnetaddress frame ETHERNETII SNAP LOOPBACK interface eth1
gateway ipxhostaddress metric metricnumber ticks ticknumber
add ipx service servicename
type servicetype
add ipx route ipxnetaddress
add ipxroute vc name
ipxnet ipxaddress metric hopcount ticks ticknumber
type servicetype
add ipxservice vc name
CLI Commands B-7
add network service servicename status
servertype servertype socket socketnumber enabled YES data “string”
closeactiveconnections TRUE FALSE
Add network service example
add networkservice CLIaccess servertype TELNETD socket
address ipaddress access RO RW
add tunnel
add snmp trapcommunity name
ipnameoraddr
address ipaddress
enabled yes
add user name
add vc name
arp output outputfilename ipnameoraddr
type servicetype
delete ipx route ipxnetaddress delete ipx service servicename
delete pat tcp vc
vcname
entries
publicaddress ipaddress
publicpoolstart ipaddress
tunnelname
bridge forwarding
DISABLE
disable ip network
DIAL
output outputfile
disable snmp
interfacename interface settings command
authentication traps
networks
ENABLE
interfacename interface settings command
using list network services
HANGUP
interfacename
LIST
HELP
HISTORY
KILL
mgmt - unknown, but filtering information exists
CLI Commands B-19
If Name - eth1, DA1 or loopback
Interface - eth1, DA1 or loopback
Prot - LOCAL or RIP
trapcommunities not list access
Quit
PAUSED COMMANDS
More or CR
Continue printing
RESOLVE
timeout timeoutvalue
PING
RENAME
set bridge
forwarddelay seconds
set command history numerical range idle timeout minutes
SAVE
address IPaddress
enabled YES NO
set dhcp relay server1
set dhcp relay server2
DNS2 IPaddress
set dns cachesize number numberretries number timeout seconds
set dhcp server
DNS1 IPaddress
routingprotocol NONE RIPV1 RIPV2
filteraccess ON OFF inputfilter filtername outputfilter filtername
set interface interfacename
B-28 APPENDIX B CLI COMMAND DESCRIPTION
CLI Commands B-29
routerid routerid
sapupdateinterval number
rip BOTH DISABLE LISTEN RESPONDONLY SEND ripagemultiplier number
rippacketsize number ripupdateinterval number
sap BOTH DISABLE LISTEN RESPONDONLY SEND sapagemultiplier number
Sets parameters for dynamic IPX networks
set network service adminname
poolmembers number
Sets parameters for configured network services
For in-depth information about CHAP and PAP, see RFC
A VPN tunnel can only be configured for MSCHAPv1 by using the CLI
Authentication Options
MPPE Options
address IPaddress access RO RW
NONE REQUIRED
location “location”
transmitauthenticationname name
set system
name “name”
message “message”
password password
sessiontimeout seconds
set user username
ip enable disable
bridging enable disable
defaultrouteoption enable disable
idletimeout seconds
CLI Commands B-37
pcr number
categoryofservice Unspecified UBR Variable VBR
set vc vcname atm
set number
Sets ATM parameters for VCs
Total errored seconds in previous 15 minutes
Total time since system reboot hours, minutes, seconds
Errored seconds since last link down
Total errored seconds in 15 minutes
Fields
Base Aging Time - time to age out a known MAC address, default
History Depth Current Prompt OCR-DSL Local Prompt OCR-DSL
settings
Problems with Name Server - internal server error
show dns counters show dns settings show filter filtername
SPECIFIC ERROR COUNTERS
OUTPUT COUNTERS
ICMP COUNTERS
INPUT COUNTERS
OUTPUT COUNTERS
show interface interfacename counters
show interface Displays
INPUT COUNTERS
settings
Fragments Needing Reassembly - # of fragmented datagrams
IP Dynamic Address Pool Begin - start of IP address range
IP Dynamic Address Pool Size - size of IP address range
INPUT COUNTERS
show ipx counters show ipx network networkname counters
OUTPUT COUNTERS
settings
show ipx rip
counters
settings
Default Gateway - default IPX router address
show ipx sap
Dynamic Address Pool Begin - starting IPX address
settings
name counters
vcname settings
name settings
vcname counters
Operational Status - opened or not opened
SETTINGS for PPP BUNDLE
SETTINGS for PPP BUNDLE 1 COMPRESSION
SETTINGS for PPP LINK 1
INPUT COUNTERS
show snmp counters Displays many SNMP statistics
OUTPUT COUNTERS
System Contact - modify using set system
System Location - modify using set system
System Descriptor - for example
OUTPUT COUNTERS
TCP SETTINGS
TCP COUNTERS
INPUT COUNTERS
verify filter
Commands
TELNET
VERIFY
Command Features
CLI Exit Commands
B-58 APPENDIX B CLI COMMAND DESCRIPTION
Comments
INDEX
Server
Input and Output filters contrasted
Static Services
Passwords
Page
Page
Page
SOFTWARE
3Com Corporation LIMITED WARRANTY
STANDARD WARRANTY SERVICE
HARDWARE
ModelDescription
FCC CLASS B STATEMENT
FCC DECLARATION OF CONFORMITY
The Interference Handbook