User Manual - Configuration Guide (Volume 3)
Versatile Routing Platform Chapter 2
Configuration of L2TP
2-7
Table VPN-2-1 Enable/disable VPDN
Operation Command
Enable VPDN to run. vpdn enable
Disable VPDN to run. no vpdn enable
Disable VPDN to run by default.
II. Create VPDN group
The information of dial-up users will be loaded on specific V PDN group, so L AC and
LNS can establish L2TP tunnel only on specific VPDN group.
Perform the following task in global configuration mode.
Table VPN-2-2 Create VPDN group
Operation Command
Create VPDN group and enter the configuration mode of VDPN group. vpdn-group group-number
Delete the existing VPDN group. no vpdn-group group-number
Do not create VPDN by default. group-number is an integer, ranging 1 to 3000.
III. Set user name and password and configure user au thentication
LAC will authenticate remote dial-in user name and password to check whether he is a
VPN user. Only after the authentication, can the request of establishing channel
connection be generated, or the user will be turn to services of other types.
As the authentication and charging at LAC side are performed via RADIUS server, the
authentication function of RADIUS server on PPP users will be started.
Table VPN-2-3 Set user name and password and configure user authentication
Operation Command
Set user name and password. user username password { 0 | 7 } password
Cancel the set user name and password. no user username
Configure to authenticate users. ppp authentication { pap | chap }
Cancel the operation to authenticate users. no ppp authentication { pap | chap }
Enable AAA. aaa-enable
Authentication method table of PPP user configuration. aaa authentication ppp { default | list-name }
{ method1} [ method2 ... ]
As L2TP is not the standard attribute of RADIUS protocol, it is necessary to add the
definition of L2TP attribute table to RADIUS server attribute domain.