Important: The commands or keywords/variables that are available are dependent on platform type, product version, and installed license(s).
roaming: Enables the sending of AAA accounting information by the LNS only for roaming subscribers.authentication { { [ allow-noauth ] [ chap chap_priority ] [ mschap mschap_priority ] [ pap pap_priority ] } | msid-auth }When the allow-noauth option is used in conjunction with commands specifying other authentication protocols and priorities to use, then if attempts to use those protocols fail, the system treats the allow-noauth option as the lowest priority.chap chap_priorityA chap_priority must be specified in conjunction with this option. Priorities specify which authentication protocol should be attempted first, second, third and so on.chap_priority must be an integer from 1 through 1000. The lower the integer, the higher the preference. CHAP is enabled by default as the highest preference.mschap mschap_priorityA mschap_priority must be specified in conjunction with this option. Priorities specify which authentication protocol should be attempted first, second, third and so on.mschap_priority must be an integer from 1 through 1000. The lower the integer, the higher the preference.pap pap_priorityA pap_priority must be specified in conjunction with this option. Priorities specify which authentication protocol should be attempted first, second, third and so on.pap_priority must be an integer from 1 through 1000. The lower the integer, the higher the preference. PAP is enabled by default as the second highest preference.no bind ip_addressmax-subscribers max_valueSpecifies the maximum number of subscribers that can be connected to this service at any time. max_value must be an integer from 1 through 2500000.The following command binds the current context interface IP address 192.168.100.10 to the current LNS service:drop-limit numSets the number of allowed source violations within a detection period before forcing a call disconnect. If num is not specified, the value is set to the default.num can be an integer from 1 through 1000000.period secsThe counters are decremented in this manner: reneg-limit counter is reduced by one (1) each time the period value is reached until the counter is zero (0); drop-limit counter is halved each time the period value is reached until the counter is zero (0). If secs is not specified, the value is set to the default.secs can be an integer from 1 through 1000000.reneg-limit numSets the number of allowed source violations within a detection period before forcing a PPP renegotiation. If num is not specified, the value is set to the default.num can be an integer from 1 through 1000000.keepalive-interval secondslocal-receive-window integerThe following command sets the local receive window to 10 control messages:max-retransmission integermax-sessions-per-tunnel integermax-tunnels integerUse the following command to set the maximum number of tunnels for the current LNS service to 20000:domain_name { @ | % | - | \ | # | / }Specifies the desired domain name alias followed immediately by a separator from the valid list. domain_name must be an alphanumeric string of from 1 through 79 characters.To specify a domain alias of mydomain@ with a separator of @, enter the following command:no peer-lac ip_addressno peer-lac ip_addressDeletes the peer LAC IP address specified by ip_address. ip_address must be entered using IPv4 dotted-decimal notation.The IP address of a specific peer LAC for the current LNS service. ip_address must be entered using IPv4 dotted-decimal notation.A network prefix and mask enabling communication with a group of peer LACs. ip_address is the network prefix expressed in IPv4 dotted-decimal notation.mask is the number of bits that defines the prefix.[encrypted]secret secretDesignates the secret which is shared between the current LNS service and the peer LAC. secret must ben alphanumeric string of 1 through 127 characters that is case sensitive.description textSpecifies the descriptive text to use to describe the specified peer LAC. text must be an alphanumeric string of 0 through 79 characters.The following command adds a peer LAC to the current LNS service with the IP address of 10.10.10.100, and specifies the shared secret to be 1b34nnf5d:The following command removes the peer LAC with the IP address of 10.10.10.200 for the current LNS service:retransmission-timeout-first integerretransmission-timeout-max integersetup-timeout secondsSpecifies the maximum time (in seconds) to wait for the setup of a session. seconds must be an integer from 1 through 1000000.When tunnel authentication is enabled, a configured shared secret is used to ensure that the LNS service is communicating with an authorized peer LAC. The shared secret is configured by the peer-lac command, the tunnel l2tp command in the Subscriber Configuration mode, or the Tunnel-Password attribute in the subscribers RADIUS profile.
|
| Cisco Systems Inc. |
| Tel: 408-526-4000 |
| Fax: 408-527-0883 |