L2TP Configuration Examples
631
b
Adopt AAA authentication.
[Router1]
aaa-enable
[Router1]
aaa authentication-scheme ppp default local
[Router1]
aaa accounting-scheme optional
c
Create an access control list and specify the encrypted L2TP data.
[Router1]
acl 101
[Router1-acl-101]
rule permit udp source 202.38.161.1 0.0.0.0
destination 202.38.161.2 0.0.0.0 destination-port equal 1701
d
Create a transform view, use DES encryption and adopt a transport mode.
[Router1]
ipsec proposal l2tptrans
[Router1-ipsec-proposal-l2tptrans]
transform esp-new
[Router1-ipsec-proposal-l2tptrans]
esp-new encryption-algorithm des
[Router1-ipsec-proposal-l2tptrans]
esp-new auth sha1-hmac-96
[Router1-ipsec-proposal-l2tptrans]
encapsulation-mode transport
e
Create a crypto policy, use IKE negotiation mode and configure IKE
pre-shared-key.
[Router1]
ipsec policy l2tpmap 10 isakmp
[Router1-ipsec-policy-l2tpmap-10]
ike pre-shared-key l2tp_ipsec
remote 202.38.160.2
[Router1-ipsec-policy-l2tpmap-10]
match address 101
[Router1-ipsec-policy-l2tpmap-10]
set peer 202.38.160.2
[Router1-ipsec-policy-l2tpmap-10]
set transform l2tptrans
f
Configure an IP address on Serial 0 interface and apply a IPSec policy.
[Router1]
interface serial 0
[Router1-Serial0]
ip address 202.38.160.1 255.255.255.0
[Router1-Serial0]
ipsec policy l2tymap
g
Configure a L2TP group and configure the related attributes.
[Router1]
l2tp enable
[Router1]
l2tp-group 1
[Router1-l2tp1]
tunnel name lac-end
[Router1-l2tp1]
start l2tp ip 202.38.160.2 fullusername vpdnuser
[Router1-l2tp1]
undo tunnel authentication
3
Configuration at Router2 (LNS side)
a
Enable AAA authentication.
[Router2]
aaa-enable
[Router2]
aaa authentication-scheme ppp default local
b
Configure the username and password that should be the same as those
configured at the LAC side.
[Router2]
local-user vpdnuser password simple Hello
c
Configure an address pool 1 in the range of 192.168.0.2 to 192.168.0.100.
[Router2]
ip pool 1 192.168.0.2 192.168.0.100
d
Configure an access control list and specify L2TP data.
[Router2]
acl 101
[Router2-acl-101]
rule permit udp source 192.168.0.0 0.0.0.255
destination 202.38.161.1 0.0.0.0
e
Create the transform view, use DES encryption and adopt the transform mode.
[Router2]
ipsec proposal l2tptrans
Summary of Contents for 3036
Page 1: ...http www 3com com 3Com Router Configuration Guide Published March 2004 Part No 10014299 ...
Page 4: ...VPN 615 RELIABILITY 665 QOS 681 DIAL UP 721 ...
Page 6: ...2 ABOUT THIS GUIDE ...
Page 7: ...I GETTING STARTED Chapter 1 3Com Router Introduction Chapter 2 3Com Router User Interface ...
Page 8: ...4 ...
Page 16: ...12 CHAPTER 1 3COM ROUTER INTRODUCTION ...
Page 34: ...30 ...
Page 60: ...56 CHAPTER 3 SYSTEM MANAGEMENT ...
Page 98: ...94 CHAPTER 6 DISPLAY AND DEBUGGING TOOLS ...
Page 110: ...106 ...
Page 114: ...110 CHAPTER 8 INTERFACE CONFIGURATION OVERVIEW ...
Page 158: ...154 CHAPTER 10 CONFIGURING WAN INTERFACE ...
Page 168: ...164 ...
Page 188: ...184 CHAPTER 13 CONFIGURING PPPOE CLIENT ...
Page 192: ...188 CHAPTER 14 CONFIGURING SLIP Router ip route static 0 0 0 0 0 0 0 0 10 110 0 1 ...
Page 248: ...244 CHAPTER 16 CONFIGURING LAPB AND X 25 ...
Page 320: ...316 ...
Page 330: ...326 CHAPTER 20 CONFIGURING IP ADDRESS ...
Page 362: ...358 CHAPTER 21 CONFIGURING IP APPLICATION ...
Page 374: ...370 CHAPTER 23 CONFIGURING IP COUNT ...
Page 406: ...402 CHAPTER 25 CONFIGURING DLSW ...
Page 408: ...404 ...
Page 452: ...448 CHAPTER 29 CONFIGURING OSPF ...
Page 482: ...478 CHAPTER 30 CONFIGURING BGP ...
Page 494: ...490 CHAPTER 31 CONFIGURING IP ROUTING POLICY ...
Page 502: ...498 ...
Page 508: ...504 CHAPTER 33 IP MULTICAST ...
Page 514: ...510 CHAPTER 34 CONFIGURING IGMP ...
Page 526: ...522 CHAPTER 36 CONFIGURING PIM SM ...
Page 528: ...524 ...
Page 532: ...528 CHAPTER 37 CONFIGURING TERMINAL ACCESS SECURITY ...
Page 550: ...546 CHAPTER 38 CONFIGURING AAA AND RADIUS PROTOCOL ...
Page 590: ...586 CHAPTER 40 CONFIGURING IPSEC ...
Page 599: ...IX VPN Chapter 42 Configuring VPN Chapter 43 Configuring L2TP Chapter 44 Configuring GRE ...
Page 600: ...596 ...
Page 638: ...634 CHAPTER 43 CONFIGURING L2TP ...
Page 649: ...X RELIABILITY Chapter 45 Configuring a Standby Center Chapter 46 Configuring VRRP ...
Page 650: ...646 ...
Page 666: ...662 ...
Page 670: ...666 CHAPTER 47 QOS OVERVIEW ...
Page 700: ...696 CHAPTER 49 CONGESTION MANAGEMENT ...
Page 706: ...702 CHAPTER 50 CONGESTION AVOIDANCE ...
Page 707: ...XII DIAL UP Chapter 51 Configuring DCC Chapter 52 Configuring Modem ...
Page 708: ...704 ...
Page 762: ...758 CHAPTER 52 CONFIGURING MODEM ...