User Manual - Configuration Guide (Volume 3)
Versatile Routing Platform Chapter 2
Configuration of L2TP
2-5
LAC LNS
WAN
PSTN/ISDN
LAC RADIUS server LNS RADIUS server
(5)Request tunnel message
user = domain
password = quidway
(6)AV PairsTunnel message
Local name(LAC)
Tunnel password
Tunnel type
LNS IP Address
Access request
(15)(20)
Access response
(16)(21)
(15)
(20)
(16)
(21)
Call setup (1)
PPP LCPSetup (2)
user CHAP challenge(3)
user CHAP response(4)
Tunnel establishment(7)
Tunnel authentication CHAP challenge(8)
LNS CHAP response(9)
Authentication Passes (10)
CHAP challenge(11)
LAC CHAP response(12)
Authentication passes (13)
user CHAP response + response identifier + PPP consultation parameter (14)
Pass (17)
Optional second time CHAP challenge(18)
CHAP response(19)
Authentication passes (22)
Figure VPN-2-3 Call setup flow of L2TP channel
V. Features of L2TP protocol
z Flexible identity authentication mechanism and high security
L2TP protocol does not provide connection security, but it can depend on the
authentication (e.g. CHAP and PAP) provided by PPP, so it has all security features of
PPP. L2TP can integrate with IPsec to fulfill data security, so it is difficult to attack the
data transmitted with L2TP. As required by specific network security, L2TP adopts
channel encryption technique, end-to-end data encryption or application layer data
encryption on it to improve data security.
z Multi-protocol transmission
L2TP transmits PPP packet. Thus multi-protocol can be encapsulated in PPP packet.
z Support the authentication of RADIUS server
LAC requires the authentication of RADIUS with user name and password. RADIUS
server is in charging of receiving authentication request of the user, fulfilling the
authentication and returning to LAC the configuration information for connect ion
establishment.
z Support internal address distribution