IMPORTANT:
IMPORTANT:
LNS Service Operation
Information Required
Source Context Configuration
| Required Information | Description |
|---|---|
|
Source context name
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric) by
which the source context will be recognized by the system.
|
|
PDN Interface Configuration
|
|
|
PDN interface name
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric) by
which the interface will be recognized by the system.
Multiple names are
needed if multiple interfaces will be configured.
These PDN interfaces
facilitates the L2TP tunnels/sessions from the LAC and
are configured in the source context.
|
|
IP address and subnet
|
These will be assigned
to the PDN interface.
Multiple addresses
and/or subnets are needed if multiple interfaces will be configured.
|
|
Physical port number
|
This specifies the
physical port to which the interface will be bound. Ports are identified
by the chassis slot number where the line card resides in, followed
by the number of the physical connector on the line card. For example,
port 17/1 identifies connector number 1 on the card in
slot 17.
A single physical
port can facilitate multiple interfaces.
|
|
Physical port description
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric) by
which the physical port will be recognized by the system.
Multiple descriptions
are needed if multiple ports will be used.
Physical ports are
configured within the source context and are used to bind logical PDN
interfaces.
|
|
Gateway IP address
|
Used when configuring
static routes from the PDN interface(s) to a specific network.
|
|
LNS service Configuration
|
|
|
LNS service name
|
This is an identification
string between 1 and 63 characters (alpha and/or numeric) by
which the LNS service will be recognized by the system.
Multiple names are
needed if multiple LNS services will be used.
LNS services are configured
in the source context.
|
|
Authentication protocols used
|
Specifies how the
system handles authentication: using a protocol (such as CHAP, PAP,
or MSCHAP), or not requiring any authentication.
|
|
Domain alias for NAI-construction
|
Specifies a context
name for the system to use to provide accounting functionality for
a subscriber session. This parameter is needed only if the system
is configured to support no authentication.
|
|
Maximum number of sessions
per tunnel
|
This defines the maximum
number of sessions supported by each tunnel facilitated by the LNS
service.
The number can be
configured to any integer value from 1 to 65535. The default is 65535.
|
|
Maximum number of tunnels
|
This defines the maximum
number of tunnels supported by the LNS service.
The number can be
configured to any integer value from 1 to 32000. The default is 32000.
|
|
Peer LAC
|
IP address or network
prefix and mask:
The IP address of
a specific peer LAC for which the LNS service terminates L2TP tunnels.
The IP address must be expressed in dotted decimal notation. Multiple
peer LACs can be configured.
Alternately, to simplify
configuration, a group of peer LACs can be specified by entering
a network prefix and a mask.
|
|
Secret:
The shared secret
used by the LNS to authenticate the peer LAC. The secret can be from
1 to 256 alpha and/or numeric characters and is case sensitive.
|
|
|
AAA Interface Configuration
|
|
|
AAA interface name
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric) by
which the interface will be recognized by the system.
Multiple names are
needed if multiple interfaces will be configured.
AAA interfaces will
be configured in the source context.
|
|
IP address and subnet
|
These will be assigned
to the AAA interface.
Multiple addresses
and/or subnets are needed if multiple interfaces will be configured.
|
|
Physical port number
|
A single physical
port can facilitate multiple interfaces.
|
|
Physical port description
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric) by
which the physical port will be recognized by the system.
Multiple descriptions
are needed if multiple ports will be used.
Physical ports are
configured within the source context and are used to bind logical AAA
interfaces.
|
|
Gateway IP address
|
Used when configuring
static routes from the AAA interface(s) to a specific network.
|
|
RADIUS Server Configuration
|
|
|
RADIUS Authentication server
|
IP Address:
Specifies the IP address
of the RADIUS authentication server the source context will communicate
with to provide subscriber authentication functions.
Multiple addresses
are needed if multiple RADIUS servers will be configured.
RADIUS authentication
servers are configured within the source context. Multiple servers
can be configured and each assigned a priority.
|
|
Shared Secret:
The shared secret
is a string between 1 and 15 characters (alpha and/or numeric) that
specifies the key that is exchanged between the RADIUS authentication
server and the source context.
A shared secret is
needed for each configured RADIUS server.
|
|
|
UDP Port Number:
Specifies the port
used by the source context and the RADIUS authentication server
for communications. The UDP port number can be any integer value
between 1 and 65535. The default value is 1812.
|
|
|
RADIUS Accounting server
|
IP Address:
Specifies the IP address
of the RADIUS accounting server that the source context will communicate
with to provide subscriber accounting functions.
Multiple addresses
are needed if multiple RADIUS servers will be configured.
RADIUS accounting
servers are configured within the source context. Multiple servers
can be configured and each assigned a priority.
|
|
Shared Secret:
The shared secret
is a string between 1 and 15 characters (alpha and/or numeric) that
specifies the key that is exchanged between the RADIUS accounting
server and the source context.
A shared secret is
needed for each configured RADIUS server.
|
|
|
UDP Port Number:
Specifies the port
used by the source context and the RADIUS Accounting server for
communications. The UDP port number can be any integer value between
1 and 65535. The default value is 1813.
|
|
|
RADIUS attribute NAS Identifier
|
Specifies the name
by which the source context will be identified in the Access-Request
message(s) it sends to the RADIUS server. The name must be between
1 and 32 alpha and/or numeric characters and is case sensitive.
|
|
RADIUS NAS IP address
|
Specifies the IP address
of the source context’s AAA interface. A secondary IP address
interface can optionally be configured.
|
|
Default Subscriber
Configuration
|
|
|
“Default” subscriber’s
IP context name
|
Specifies the name
of the egress context on the system that facilitates the PDN ports.
NOTE: For this
configuration, the IP context name should be identical to the name
of the destination context.
|
Destination Context Configuration
| Required Information | Description |
|---|---|
|
Destination context
name
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric)
by which the destination context will be recognized by the system.
NOTE: For this
configuration, the destination context name should not match the
domain name of a specific domain.
|
|
PDN Interface Configuration
|
|
|
PDN interface name
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric)
by which the interface will be recognized by the system.
Multiple names are
needed if multiple interfaces will be configured.
PDN interfaces are
used to connect to a packet network and are configured in the destination
context.
|
|
IP address and subnet
|
These will be assigned
to the PDN interface.
Multiple addresses
and/or subnets are needed if multiple interfaces will be configured.
|
|
Physical port number
|
A single physical
port can facilitate multiple interfaces.
|
|
Physical port description(s)
|
This is an identification
string between 1 and 79 characters (alpha and/or numeric)
by which the physical port will be recognized by the system.
Multiple descriptions
will be needed if multiple ports will be used.
Physical ports are
configured within the destination context and are used to bind logical
PDN interfaces.
|
|
Gateway IP address(es)
|
Used when configuring
static routes from the PDN interface(s) to a specific network.
|
|
IP Address Pool Configuration
(optional)
|
|
|
IP address pool name(s)
|
If IP address pools
will be configured in the destination context(s), names or identifiers
will be needed for them. The pool name can be between 1 and 31 alpha and/or
numeric characters and is case sensitive.
|
|
IP pool addresses
|
An initial address
and a subnet, or a starting address and an ending address, are required
for each configured pool. The pool will then consist of every possible address
within the subnet, or all addresses from the starting address to
the ending address.
The pool can be configured
as public, private, or static.
|
How This Configuration Works
IMPORTANT:
Creating and Binding LNS Service
configure
context
<dest_ctxt_name>
-noconfirm
lns-service
<lns_svc_name>
-noconfirm
bind
address <ip_address> [ max-subscribers
<max_subscriber> ]
end
Configuring Authentication Parameters for LNS Service
Configuring Tunnel and Session Parameters for LNS Service
Configuring Peer LAC servers for LNS Service
Configuring Domain Alias for AAA Subscribers
configure
context
<dest_ctxt_name>
-noconfirm
lns-service
<lns_svc_name>
-noconfirm
nai-construct
domain <domain_alias>
end
show lns-service name service_name
The output of this
command displays the configuration of the LNS service and should
appear similar to that shown below.Service name: testlns Context: test Bind: Not Done Local
IP Address: 0.0.0.0 First
Retransmission Timeout: 1 (secs) Max
Retransmission Timeout: 8 (secs) Max
Retransmissions: 5 Setup
Timeout: 60 (secs) Max
Sessions: 500000 Max Tunnels: 32000 Max
Sessions Per Tunnel: 65535 Keep-alive
Interval: 60 Control Receive
Window: 16 Data
Sequence Numbers: Enabled Tunnel
Authentication: Enabled Tunnel Switching: Enabled Max
Tunnel Challenge Length: 16 PPP
Authentication: CHAP
1 PAP 2 Allow
Noauthentication: Disabled MSID Authentication: Disabled No
NAI Construct Domain defined No
Default Subscriber defined IP
Src Violation Reneg Limit: 5 IP
Src Violation Drop Limit: 10 IP
Src Violation Period: 120 (secs) Service
Status: Not started Newcall Policy: None