User Manual - Configuration Guide (Volume 3)

Chapter 2

Versatile Routing Platform

Configuration of L2TP

LAC RADIUS server

LNS RADIUS server

 

(5)Request tunnel message

user = domain password = quidway

 

 

Access request

 

 

(15)(20)

(6)AV PairsTunnel message

 

Access response

Local name(LAC)

 

 

(16)(21)

Tunnel password

 

(15)

(16)

Tunnel type

LNS IP Address

(20)

(21)

 

PSTN/ISDN

WAN

LAC

LNS

 

Call setup (1)

PPPLCPSetup (2) user CHAP challenge(3) user CHAP response(4)

Tunnel establishment(7)

Tunnel authentication CHAP challenge(8)

LNS CHAP response(9)

Authentication Passes (10)

CHAP challenge(11)

LAC CHAP response(12)

Authentication passes (13)

user CHAP response + response identifier + PPP consultation parameter (14) Pass (17)

Optional second time CHAP challenge(18)

CHAP response(19)

Authentication passes (22)

Figure VPN-2-3Call setup flow of L2TP channel

V. Features of L2TP protocol

zFlexible identity authentication mechanism and high security

L2TP protocol does not provide connection security, but it can depend on the authentication (e.g. CHAP and PAP) provided by PPP, so it has all security features of

PPP.L2TP can integrate with IPsec to fulfill data security, so it is difficult to attack the data transmitted with L2TP. As required by specific network security, L2TP adopts channel encryption technique, end-to-end data encryption or application layer data encryption on it to improve data security.

zMulti-protocol transmission

L2TP transmits PPP packet. Thus multi-protocol can be encapsulated in PPP packet.

zSupport the authentication of RADIUS server

LAC requires the authentication of RADIUS with user name and password. RADIUS server is in charging of receiving authentication request of the user, fulfilling the authentication and returning to LAC the configuration information for connection establishment.

zSupport internal address distribution

2-5

Page 25
Image 25
Huawei v200r001 user manual Features of L2TP protocol, Figure VPN-2-3Call setup flow of L2TP channel