User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
142
Mode: lac
LAC Setting:
LNS connect address: 0.0.0.0
User auth key/cert: Not set
Use the -sessions switch to view any active L2TP sessions,
including Tunnel ID and Session ID:
# show l2tp -sessions
Current L2TP Settings:
Enabled: Y
Mode: lns
LNS Setting:
Local address: 192.168.1.1
LAC IP range min: 192.168.1.2
LAC IP range max: 192.168.2.254
User auth key/cert: l2tp
Tunnel and session information:
Tunnel Id Peer IP Our IP State Session Id
15144 172.26.58.140 172.26.58.134 ESTABLISHED 59324
You can delete all L2TP sessions, only those for a particular
Tunnel ID, or a single session, using
del l2tp-session.
# del l2tp-session -all|-tunnelid
<tunnelId>
|-sessionid
<sessionId>
You must be logged on to an
administrator
-level account
(refer to Section 2.2) to change configuration settings.
4.5 Authentication and Timeouts
The Mesh Point is equipped with an internal authentication
service (Section 4.5.2) and can be configured to use an
external Fortress RADIUS server (internal to another Mesh
Point) or a 3rd-party freeRADIUS or Microsoft® IAS® (Internet
Authentication Service) server, as described below.
Timeouts can be configured for Mesh Points that are not using
RADIUS (Section 4.5.5) and in the internal RADIUS server
(Section 4.5.2 and Section 4.5.3).
4.5.1 Authentication Servers
Use
show
auth
to display currently configured authentication
servers:
> show auth
[Authentication Server List]
Name Priority Mode Type AuthType IPaddr PortNumber Description AdminState
------ -------- -------- ---------- ----------------- ------------ ---------- ----------- ----------
RADIUS 1 external thirdParty USER_DEVICE|8021X 192.168.1.22 1812 active
[Highest Priority Active Authentication Server Entry For Each Type]
AuthType IpAddr AdminState Type
----------- ------------ ---------- ----------