xviii MAX 6000/3000 Network Configuration Guide
Contents
Chapter 11 Setting Up Virtual Private Networks............................................ 11-1
Introduction to Virtual Private Networks............................................................................. 11-1
Configuring ATMP tunnels................................................................................................. 11-2
How the MAX creates ATMP tunnels.......................................................................... 11-2
Setting the UDP port..................................................................................................... 11-3
Setting an MTU limit.................................................................................................... 11-3
How link compression affects the MTU................................................................ 11-4
How ATMP tunneling causes fragmentation........................................................ 11-4
Pushing the fragmentation task to connection end-points..................................... 11-4
Forcing fragmentation for interoperation with outdated clients................................... 11-4
Router and gateway mode............................................................................................. 11-5
Configuring the Foreign Agent..................................................................................... 11-5
Understanding the Foreign Agent parameters and attributes................................ 11-7
Example of configuring a Foreign Agent (IP)....................................................... 11-9
Example of configuring a Foreign Agent (IPX).................................................. 11-10
Configuring a Home Agent......................................................................................... 11-11
Configuring a Home Agent in router mode......................................................... 11-11
Configuring a Home Agent in gateway mode..................................................... 11-15
Specifying the tunnel password........................................................................... 11-22
Setting an idle timer for unused tunnels.............................................................. 11-22
Configuring the MAX as an ATMP multimode agent ............................................... 11-22
Supporting mobile client routers (IP only)................................................................. 11-25
Home Agent in router mode................................................................................ 11-26
Home Agent in gateway mode............................................................................ 11-26
ATMP connections that bypass a Foreign Agent....................................................... 11-26
Configuring PPTP tunnels for dial-in clients..................................................................... 11-27
How the MAX works as a PAC.................................................................................. 11-27
Understanding the PPTP PAC parameters.................................................................. 11-28
Enabling PPTP..................................................................................................... 11-28
Specifying a PRI line for PPTP calls and the PNS IP address............................ 11-28
Example of a PAC configuration................................................................................ 11-28
Example of a PPTP tunnel across multiple POPs....................................................... 11-29
Routing a terminal-server session to a PPTP server................................................... 11-30
Configuring L2TP tunnels for dial-in clients..................................................................... 11-31
Elements of L2TP tunneling....................................................................................... 11-31
How the MAX creates L2TP tunnels .................................................................. 11-32
Proxy LCP and authentication support for L2TP................................................ 11-32
LAC and LNS mode............................................................................................ 11-33
Tunnel authentication.......................................................................................... 11-33
Client authentication............................................................................................ 11-33
Flow control......................................................................................................... 11-34
Using the Tunnel-Assignment-ID (82) RADIUS attribute for L2TP......................... 11-34
Configuration of the MAX as an LAC....................................................................... 11-36
Understanding the L2TP LAC parameters.......................................................... 11-36
Configuring the MAX ......................................................................................... 11-37
Using multiple L2TP system names........................................................................... 11-38
Overview of RADIUS attribute-value pairs........................................................ 11-38
Example of tunnel authentication........................................................................ 11-39
Example of connection-based tunnel authentication........................................... 11-39
Creating parallel L2TP tunnels to the same end point......................................... 11-41
Configuration of the MAX as an LNS........................................................................ 11-43
Using DNS list attempts for L2F and L2TP............................................................... 11-44