User Manual - Configuration Guide (Volume 3)

Chapter 2

Versatile Routing Platform

Configuration of L2TP

LNS can be put behind Intranet firewall. It can dynamically distribute and manage the addresses of remote users and support the application of private addresses (RFC1918). The distributed addresses for remote users are private addresses in enterprise instead of Internet addresses, thus the addresses can be easily managed and the security can also be improved.

zFlexible network charging

Charge in both LAC and LNS at the same time, that is, in ISP (to generate bills) and Intranet gateway (to pay for charge and audit). L2TP can provide such charging data as transmitted packet number, byte number, start time and end time of the connection. And it can easily perform network charging according to these data.

zReliability

L2TP supports backup LNS. When an active LNS is inaccessible, LAC (access server) can reconnect the backup LNS to improve the reliability and fault tolerance of VPN service.

2.2 Configuring L2TP

2.2.1 L2TP Configuration Task List

L2TP configuration task can be divided into the configurations at LAC and LNS sides.

I. Configuration at LAC side

zStart/Disable VPDN.

zCreate VPDN group.

zSet to originate L2TP connection request and LNS addresses.

zSet user name and password.

II. Configuration at LNS side

zStart/Disable VPDN.

zCreate VPDN group.

zCreate or delete virtual interface template.

zSet the name of receiving channel opposite end.

III. Optional configuration

zSet local name.

zSet channel authentication and password.

zForce local end to perform CHAP authentication.

zForce LCP to re-negotiation.

zSet domain name delimiter and search sequence.

zForce to disconnect channel.

2.2.2Configuring at LAC Side

I.Enable/disable VPDN

Perform the following task in global configuration mode.

2-6

Page 26
Image 26
Huawei v200r001 user manual Configuring L2TP, 1 L2TP Configuration Task List, Configuring at LAC Side