H3C MSR1000[2600][3600] Routers Configuration Examples All-in-One-R9141-6W100

HomeSupportConfigure & DeployConfiguration ExamplesH3C MSR1000[2600][3600] Routers Configuration Examples All-in-One-R9141-6W100
Table of Contents
Related Documents
61-LAC-Auto-Initiated L2TP Tunnel Configuration Examples

H3C Routers

LAC-Auto-Initiated L2TP Tunnel Configuration Examples

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Copyright © 2024 New H3C Technologies Co., Ltd. All rights reserved.

No part of this manual may be reproduced or transmitted in any form or by any means without prior written consent of New H3C Technologies Co., Ltd.

Except for the trademarks of New H3C Technologies Co., Ltd., any trademarks that may be mentioned in this document are the property of their respective owners.

The information in this document is subject to change without notice.



Introduction

The following information provides LAC-auto-initiated L2TP tunnel configuration examples.

Prerequisites

The following information applies to Comware 9-based router. Procedures and information in the examples might be slightly different depending on the software or hardware version of the routers.

The configuration examples were created and verified in a lab environment, and all the devices were started with the factory default configuration. When you are working on a live network, make sure you understand the potential impact of every command on your network.

The following information is provided based on the assumption that you have basic knowledge of L2TP.

Example: Configuring an LAC-auto-initiated L2TP tunnel

Network configuration

As shown in Figure 1, Host accesses the network on the right of the LNS through an L2TP tunnel. Establish an LAC-auto-initiated L2TP tunnel between the LAC and LNS.

Figure 1 Network diagram

Analysis

To create an L2TP tunnel on the LNS after receiving a valid tunnel setup request from the LAC, enable tunnel authentication on both the LNS and LAC, and configure parameters such as PPP users and Virtual-Template interfaces.

Software versions used

This configuration example was created and verified on R9141P16 of the MSR2630E-X1 device.

Procedures

Configuring the LNS

# Assign IP addresses to interfaces.

<LNS> system-view

[LNS] interface gigabitethernet 1/0/1

[LNS-GigabitEthernet1/0/1] ip address 10.1.0.1 255.255.255.0

[LNS-GigabitEthernet1/0/1] quit

[LNS] interface gigabitethernet 1/0/2

[LNS-GigabitEthernet1/0/2] ip address 3.3.3.2 255.255.255.0

[LNS-GigabitEthernet1/0/2] quit

# Configure a local user named pc of the network type, set the password to hello, and set the service type to PPP.

[LNS] local-user pc class network

[LNS-luser-network-pc] password simple hello

[LNS-luser-network-pc] service-type ppp

[LNS-luser-network-pc] quit

# Create VT interface 1, and assign IP address 192.168.0.20/24 to the VT interface. Configure the PPP authentication method as PAP on the VT interface, and specify the VT interface to allocate address 192.168.0.2 to the PPP user.

[LNS] interface virtual-template 1

[LNS-Virtual-Template1] ip address 192.168.0.20 255.255.255.0

[LNS-Virtual-Template1] ppp authentication-mode pap

[LNS-Virtual-Template1] remote address 192.168.0.2

[LNS-Virtual-Template1] quit

# Configure domain system to perform local authentication for the PPP user.

[LNS] domain system

[LNS-isp-system] authentication ppp local

[LNS-isp-system] quit

# Enable L2TP, and create L2TP group 1 in LNS mode.

[LNS] l2tp enable

[LNS] l2tp-group 1 mode lns

# Configure the local tunnel name as lns on the LNS and specify VT interface 1 for receiving calls from the peer named LAC.

[LNS-l2tp1] tunnel name lns

[LNS-l2tp1] allow l2tp virtual-template 1 remote lac

# Enable tunnel authentication, and set the tunnel authentication key to aabbcc.

[LNS-l2tp1] tunnel authentication

[LNS-l2tp1] tunnel password simple aabbcc

[LNS-l2tp1] quit

# Configure a private network route for accessing the LAC, so that the packets to the PPP user are forwarded through the L2TP tunnel.

[LNS] ip route-static 10.2.0.0 24 192.168.0.2

Configuring the LAC

# Enable L2TP.

<LAC> system-view

[LAC] l2tp enable

# Assign IP addresses to interfaces.

[LAC] interface gigabitethernet 1/0/1

[LAC-GigabitEthernet1/0/1] port link-mode route

[LAC-GigabitEthernet1/0/1] ip address 10.2.0.1 255.255.255.0

[LAC-GigabitEthernet1/0/1] quit

[LAC] interface gigabitethernet 1/0/2

[LAC-GigabitEthernet1/0/2] port link-mode route

[LAC-GigabitEthernet1/0/2] ip address 3.3.3.1 255.255.255.0

[LAC-GigabitEthernet1/0/2] quit

# Create L2TP group 1 in LAC mode.

[LAC] l2tp-group 1 mode lac

# Configure the local tunnel name as LAC, and specify LNS IP address 3.3.3.2.

[LAC-l2tp1] tunnel name lac

[LAC-l2tp1] lns-ip 3.3.3.2

# Enable tunnel authentication, and set the tunnel authentication key to aabbcc.

[LAC-l2tp1] tunnel authentication

[LAC-l2tp1] tunnel password simple aabbcc

[LAC-l2tp1] quit

# Create interface virtual-PPP 1. On the interface, configure the PPP username as pc and password as hello, and configure the PPP authentication mode as PAP.

[LAC] interface Virtual-PPP 1

[LAC-Virtual-PPP1] ip address ppp-negotiate

[LAC-Virtual-PPP1] ppp pap local-user pc password simple hello

[LAC-Virtual-PPP1] quit

# Configure a private network route, so that the packets to the external network are forwarded through the L2TP tunnel.

[LAC] ip route-static 10.1.0.0 24 Virtual-PPP 1

# Trigger the LAC to initiate an L2TP tunnel setup request automatically, and use the tunnel parameters configured in L2TP group 1 when setting up the tunnel.

[LAC] interface Virtual-ppp1

[LAC-Virtual-PPP1] l2tp-auto-client l2tp-group 1

[LAC-Virtual-PPP1] quit

Verifying the configuration

# On the LNS, execute the display l2tp session command to display the established L2TP sessions.

[LNS] display l2tp session

LocalSID    RemoteSID    LocalTID    State

9400        1            36406       Established

# On the LNS, execute the display l2tp tunnel command to view the established L2TP tunnels.

[LNS] display l2tp tunnel

LocalTID RemoteTID State        Sessions RemoteAddress   RemotePort RemoteName

36406    13        Established  1        3.3.3.1         1701       lac

Configuration files

·     LNS:

#

interface GigabitEthernet1/0/1

 port link-mode route

 ip address 10.1.0.1 255.255.0.0

#

interface GigabitEthernet1/0/2

 port link-mode route

 ip address 3.3.3.2 255.255.255.0

#

 ip route-static 10.2.0.0 24 192.168.0.2

#

local-user pc class network

 password cipher $c$3$tUCIDRzQtW17DGjt8zjletI9YfXQnNf3

 service-type ppp

 authorization-attribute user-role network-operator

#

l2tp-group 1 mode lns

 allow l2tp virtual-template 1 remote lac

 tunnel name lns

 tunnel password cipher $c$3$B09LxThNxJFm5UL+stnd3gnPNLffshOzMg==

#

l2tp enable

#

·     LAC:

#

interface Virtual-PPP1

 ppp pap local-user pc password cipher $c$3$5VijMUTzyEreI02qAkTT3jliyHnJYg86

 ip address ppp-negotiate

 l2tp-auto-client l2tp-group 1

#

interface GigabitEthernet1/0/1

 port link-mode route

 ip address 10.2.0.1 255.255.255.0

#

interface GigabitEthernet1/0/2

 port link-mode route

 ip address 3.3.3.1 255.255.255.0

#

 ip route-static 10.1.0.0 24 Virtual-PPP1

#

l2tp-group 1 mode lac

 lns-ip 3.3.3.2

 tunnel name lac

 tunnel password cipher $c$3$ZQaYutqU2rIW/2+D+jaDn+5fsDtE3YXs6A==

#

l2tp enable

#

Related documentation

·     Layer 2—WAN Access Configuration Guide in H3C MSR1000[2600][3600] Routers Configuration Guides (V9)

·     Layer 2—WAN Access Command Reference in H3C MSR1000[2600][3600] Routers Command References (V9)

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网