R3303-HP HSR6800 Routers Layer 2 - WAN Configuration Guide

79
L2TP-based EAD is usually used for remote users. For LAN users, deploy portal authentication.
For information about packet-filter firewalls, AAA, RADIUS, and portal authentication, see Security
Configuration Guide.
Protocols and standards
RFC 1661, The Point-to-Point Protocol (PPP)
RFC 1918, Address Allocation for Private Internets
RFC 2661, Layer Two Tunneling Protocol "L2TP"
L2TP configuration task list
When configuring L2TP, perform the following operations:
1. Determine the network devices needed according to the networking environment. For
NAS-initiated mode and LAC-auto-initiated mode, configure both the LAC and the LNS. For
client-initiated mode, you only need to configure the LNS.
2. Configure the devices accordingly based on the intended role (LAC or NAS) on the network.
To configure a device as an LAC in NAS-initiated or LAC-auto-initiated mode, complete the following
tasks:
Task Remarks
Configuring basic L2TP capability
Enable L2TP
Required. Create an L2TP group
Specify the local name of the tunnel
Configuring an LAC
Configuring an LAC to initiate
tunneling requests for specified
users
Required.
Configuring an LAC to transfer AVP
data in hidden mode
Optional.
Configuring AAA authentication for
VPN users on LAC side
Required.
Configuring L2TP connection
parameters
Configuring L2TP tunnel
authentication
Optional.
Setting the hello interval
Enabling tunnel flow control
Disconnecting tunnels by force
To configure a device as an LNS in NAS-initiated, client-initiated, or LAC-auto-initiated mode, complete
the following tasks:
Task Remarks
Configuring basic L2TP capability
Enable L2TP
Required.
Create an L2TP group