R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
117
NOTE:
For more information about local user configuration and domain configuration, see
Access Control
Configuration Guide
.
To configure the authenticatee:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter interface view.
interface interface-type
interface-number
N/A
3. Assign a username to the
CHAP authenticatee.
ppp chap user username
The username you assign to the
authenticatee must be the same as
the local username you assign to
the authenticatee on the
authenticator.
4. Set the default CHAP
authentication password.
ppp chap password { cipher |
simple } password
The password you set for the
authenticatee must be the same as
the password you set for the
authenticatee on the authenticator.
Configuring MS-CHAP or MS-CHAP-V2
authentication
NOTE:
In MS-CHAP or MS-CHAP-V2 authentication, a HP device can only be an authenticator
L2TP supports the MS-CHAP authentication but does not support the MS-CHAP-V2 authentication.
Password change in MS-CHAP-V2 authentication does not support local authentication, but is used onl
y
in RADIUS authentication.
To configure the authenticator for MS-CHAP or MS-CHAP-V2 authentication:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Create a VT interface
and enter its view.
interface virtual-template number N/A
3. Configure the local
device to authenticate
the peer by using
MS-CHAP or
MS-CHAP-V2.
ppp authentication-mode { ms-chap |
ms-chap-v2 } [ [ call-in ] domain
isp-name ]
By default, PPP authentication is
disabled.
4. Return to system view.
quit N/A
5. Create a local user
account for the
authenticatee and enter
local user view.
local-user username N/A