R0106-HP MSR Router Series Layer 2 - WAN Configuration Guide(V7)
59
Figure 20 NAS-initiated tunneling mode
A NAS-initiated tunnel has the following characteristics:
• The remote system only needs to support PPP, and does not need to support L2TP.
• Authentication and accounting of the remote system can be implemented on the LAC or the LNS.
Figure 21 Establishment process for NAS-initiated tunnels
As shown in Figure 21, the following workflow is used to establish a NAS-initiated tunnel:
1. A remote system (Host A) initiates a PPP connection to the LAC (Device A).
2. The remote system and LAC perform PPP LCP negotiation.
3. The LAC authenticates PPP user information of Host A by using PAP or CHAP.
(1) Call setup
(2) LCP negotiation
(3) PAP or CHAP
authenticaion
(4) Access request
(5) Access accept
(6) Tunnel setup request
(7) CHAP authentication (challenge/response)
(9) Send user information and LCP negotiation
parameters
(12) CHAP authentication (challenge/response)
(10) Access request
(11) Acesss accept
(13) Access request
(14) Acesss accept
(15) Authentication passes, and assign an IP address
LAC
Device A
LNS
Device B
RADIUS server A RADIUS server B
Remote system
Host A
(16) Access the enterprise network
(8) Setup a session