User Manual - Configuration Guide (Volume 3)

Chapter 2

Versatile Routing Platform

Configuration of L2TP

 

Table VPN-2-1Enable/disable VPDN

 

 

 

 

 

Operation

Command

 

 

 

 

Enable VPDN to run.

vpdn enable

 

Disable VPDN to run.

no vpdn enable

Disable VPDN to run by default.

II. Create VPDN group

The information of dial-up users will be loaded on specific VPDN group, so LAC and LNS can establish L2TP tunnel only on specific VPDN group.

Perform the following task in global configuration mode.

Table VPN-2-2Create VPDN group

Operation

Command

 

 

Create VPDN group and enter the configuration mode of VDPN group.

vpdn-groupgroup-number

Delete the existing VPDN group.

no vpdn-group group-number

Do not create VPDN by default. group-numberis an integer, ranging 1 to 3000.

III. Set user name and password and configure user authentication

LAC will authenticate remote dial-in user name and password to check whether he is a VPN user. Only after the authentication, can the request of establishing channel connection be generated, or the user will be turn to services of other types.

As the authentication and charging at LAC side are performed via RADIUS server, the authentication function of RADIUS server on PPP users will be started.

Table VPN-2-3Set user name and password and configure user authentication

Operation

Command

 

 

Set user name and password.

user username password { 0 7 } password

Cancel the set user name and password.

no user username

Configure to authenticate users.

ppp authentication { pap chap }

Cancel the operation to authenticate users.

no ppp authentication { pap chap }

Enable AAA.

aaa-enable

Authentication method table of PPP user configuration.

aaa authentication ppp { default list-name}

{ method1} [ method2 ... ]

 

As L2TP is not the standard attribute of RADIUS protocol, it is necessary to add the definition of L2TP attribute table to RADIUS server attribute domain.

2-7

Page 27
Image 27
Huawei v200r001 user manual II. Create Vpdn group, Disable Vpdn to run by default