Important: The commands or keywords/variables that are available are dependent on platform type, product version, and installed license(s).
This keyword works in conjunction with the local-hostname hostname keyword applied via the tunnel l2tp command in APN Configuration mode.When Tunnel parameters are not received from the RADIUS Server, Tunnel parameters configured in an APN are considered for the LNS peer selection. When APN configuration is selected, the local-hostname configured with the tunnel l2tp command in the APN for the LNS peer will be used as an LAC Hostname.no bind ip_addressThe following command binds the local end point IP address 10.10.10.100 to the LAC service in the current context:keepalive-interval secondslocal-receive-window integerThe following command sets the local receive window to 10 control messages:max-retransmission integerThe following command sets the maximum number of retransmissions of a control message to a peer to 7:max-sessions-per-tunnel integermax-tunnels integerUse this command to set the maximum number tunnels that this LAC service can support at any on time.Use the following command to set the maximum number of tunnels for the current LAC service to 20000:peer-lns ip_address [encrypted] secret secret [crypto-map map_name { [encrypted] isakmp-secret secret } ] [ description text ] [ preference integer]no peer-lns ip_addressno peer-lns ip_addressDeletes the peer LNS at the IP address specified by ip_address. ip_address must be entered in IPv4 dotted-decimal notation.The IP address of the peer LNS for the current LAC service. ip_address must be entered in IPv4 dotted-decimal notation.Designates the secret which is shared between the current LAC service and the peer LNS. secret must be an alphanumeric string of 1 through 256 characters that is case sensitive.encrypted secret secret: Specifies that encryption should be used when communicating the secret with the peer LNS.map_name is the name of a crypto map that has been configured in the current context. map_name must be an alphanumeric string of 1 through 127 characters that is case sensitive.isakmp-secret secret: The pre-shared key for IKE. secret must be an alphanumeric string of 1 through 127 characters that is case sensitive.encrypted isakmp-secret secret: The pre-shared key for IKE. Encryption must be used when sending the key. secret must be an alphanumeric string of 1 through 127 characters.description textSpecifies the descriptive text to use to describe the specified peer LNS. text must be an alphanumeric string of 0 through 79 characters.preference integerThis sets the priority of the peer LNS if multiple peer LNSs are configured. integer must be an integer from 1 through 128.The following command adds a peer LNS to the current LAC service with the IP address of 10.10.10.100, sets encryption on, specifies the shared secret to be 1b34nnf5d, and sets the preference to 3:The following command removes the peer LNS with the IP address of 10.10.10.200 for the current LAC service:retransmission-timeout-first integerretransmission-timeout-max integerinteger is the maximum time (in seconds) to wait before retransmitting control messages expressed as e an integer from 1 through 100.Caution: Changing this configuration, while the service is already running, will cause restart of the service.
Important: When this feature is enabled and the show subscribers all command is invoked, the framed-IP-address is displayed for the PDSN Simple IP subscriber in the output display.
The default configuration has the selection-key as none. Hence, LAC will not make use of key to choose a tunnel with LNS in default setup.The maximum number of sessions, as configured via the max-sessions-per-tunnel command, is applicable for each tunnel created through this command. By default, each tunnel supports 512 sessions.Enables tunnel authentication. When tunnel authentication is enabled, a configured shared secret is used to ensure that the LAC service is communicating with an authorized peer LNS. The shared secret is configured by the peer-lns command in the LAC Service Configuration mode, the tunnel l2tp command in the Subscriber Configuration mode, or the Tunnel-Password attribute in the subscribers RADIUS profile.
|
| Cisco Systems Inc. |
| Tel: 408-526-4000 |
| Fax: 408-527-0883 |