Specifying to send accm, Configuring l2tp connection parameters, Configuring l2tp tunnel authentication – H3C Technologies H3C SecPath F1000-E User Manual
Page 49: Setting the hello interval
16
Specifying to Send ACCM
According to RFC 2661, the Asynchronous Control Character Map (ACCM) AVP enables an LNS to
inform the LAC of the ACCM that the LNS has negotiated with the PPP peer.
In practice, LACs from some manufacturers support ACCM, while LACs from some others do not.
Therefore, an LNS needs to know whether it should send ACCM.
By default, an LNS sends ACCM. If the LAC does not support ACCM, configure the LNS not to send
ACCM.
Follow these steps to configure an LNS to send ACCM:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Specify to send ACCM
l2tp sendaccm enable
Required
By default, an LNS sends ACCM.
Configuring L2TP Connection Parameters
These L2TP connection parameter configuration tasks apply to both LACs and LNSs and are optional.
Configuring L2TP Tunnel Authentication
You can enable tunnel authentication to allow the LAC and LNS to authenticate each other. Either the
LAC or the LNS can initiate a tunnel authentication request. To implement tunnel authentication, enable
tunnel authentication on both the LAC and LNS, and configure the same non-null password on them.
Follow these steps to configure L2TP tunnel authentication:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter L2TP group view
l2tp-group group-number
—
Enable L2TP tunnel
authentication
tunnel authentication
Optional
Enabled by default
Configure the tunnel
authentication password
tunnel password { simple |
cipher } password
Required
The password is null by default.
NOTE:
•
To ensure tunnel security, enable tunnel authentication.
•
To change the tunnel authentication password, do so after tearing down the tunnel. Otherwise, your
change does not take effect.
Setting the Hello Interval
To check the connectivity of a tunnel, the LAC and LNS regularly send each other Hello packets. Upon
receipt of a Hello packet, the LAC or LNS returns a response packet. If the LAC or LNS receives no Hello