Configuring L2TP Services

Tunnel Management

The Bay Networks tunnel management server (TMS), which resides at the ISP network, stores the TMS database. This database contains the remote users’ domain name, the IP address information of each LNS, and other tunnel addressing information that the network administrator configures. The LAC requests this information from the TMS to construct the L2TP tunnel.

When the LAC receives a call, it forwards the domain name to the TMS. The domain name is the portion of the user’s address that specifies a particular location in the network. For example, if the user name is jdoe@baynetworks.com, baynetworks.com is the domain name. The TMS looks up the domain name and verifies that the remote user is an L2TP user. The TMS also provides the LAC with the addressing information required to establish a tunnel to the correct LNS.

Note: The domain name referred to in this guide is a domain identifier that does not follow a specific format. It is not related to any Domain Name System (DNS) protocol requirements.

Tunnel Authentication

For security purposes, you can enable the LNS to perform tunnel authentication. Tunnel authentication is the process of negotiating the establishment of a tunnel.

During tunnel authentication, the LNS identifies the L2TP client or LAC by comparing the LAC’s tunnel authentication password with its own password. If the passwords match, the LNS permits the LAC to establish a tunnel.

The LAC does not send the tunnel authentication password as a plain-text message. The exchange of passwords works much like the PPP Challenge Handshake Authentication Protocol (CHAP). When one side receives a challenge, it responds with a value that is calculated based on the authentication password. The receiving side matches the value against its own calculation. If the values match, authentication is successful.

Tunnel authentication occurs in both directions, which means that the LAC and LNS both try to verify the other’s identity.

1-12

303532-A Rev 00

Page 28
Image 28
Nortel Networks L2TP manual Tunnel Management, Tunnel Authentication

L2TP specifications

Nortel Networks L2TP, or Layer 2 Tunneling Protocol, is a widely recognized networking protocol that enables the tunneling of data over various networks. Initially developed as an extension of the Point-to-Point Tunneling Protocol (PPTP), L2TP integrates components from both PPTP and Layer 2 Forwarding (L2F). Nortel Networks played a significant role in the development and implementation of L2TP, making it a prominent choice for service providers and enterprise networks seeking secure and efficient connectivity.

One of the primary features of L2TP is its ability to encapsulate data packets, allowing the transport of PPP (Point-to-Point Protocol) frames without necessitating the traditional point-to-point connections. This means L2TP can operate across different networks, facilitating remote access connections and VPNs (Virtual Private Networks). As a result, organizations can achieve greater flexibility in managing their communications infrastructure.

Another key characteristic of L2TP is its support for both IPv4 and IPv6, ensuring compatibility with current and future networking environments. L2TP operates at the link layer of the OSI model, which means it functions between the data link and network layers, making it versatile for various applications. By using UDP (User Datagram Protocol) as a transport protocol, L2TP ensures efficient data transmission while maintaining lower latencies.

Security is a critical aspect of L2TP. While L2TP itself does not provide encryption, it is often paired with IPSec (Internet Protocol Security) for enhanced security protocols. This combination offers both tunneling and encryption, creating a secure framework for transmitting sensitive information across potentially insecure networks, such as the Internet.

L2TP also features various authentication methods, allowing for robust access control. It supports various schemes like PAP (Password Authentication Protocol) and CHAP (Challenge Handshake Authentication Protocol), giving network administrators a range of options to ensure the legitimacy of users accessing the network.

In summary, Nortel Networks L2TP is a powerful tunneling protocol known for its flexibility, compatibility, and security features. Its ability to encapsulate data for efficient transport makes it ideal for remote access and VPN applications. As organizations continue to demand secure, seamless connectivity, L2TP remains a resilient choice within the shifting landscape of networking technologies.