Avaya Configuring and Troubleshooting Bay Dial VPN (DVS) Networks Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Software Avaya Configuring and Troubleshooting Bay Dial VPN (DVS) Networks herunter. Avaya Configuring and Troubleshooting Bay Dial VPN (DVS) Networks User's Manual [en] Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 188
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - VPN Services

Part No. 302272-A Rev. 00June 1998BayRS Version 12.20Site Manager Software Version 6.20 Configuring and Troubleshooting Bay Dial VPN Services

Seite 3

Configuring and Troubleshooting Bay Dial VPN Services7-2 302272-A Rev. 005.Specify the IP address for this frame relay or PPP interface.This is the

Seite 4

Configuring the Layer 3 Gateway302272-A Rev. 00 7-3 c.Specify the keys associated with this SPI value.Each SPI value has a 128-bit key associated wi

Seite 5 - Contents

Configuring and Troubleshooting Bay Dial VPN Services7-4 302272-A Rev. 00h.Enter the IP address of the RADIUS server to which this client will conne

Seite 6

Configuring the Layer 3 Gateway302272-A Rev. 00 7-5 d.Specify the address of one or more DHCP servers on the home nework.Refer to Chapter 8 for addi

Seite 8

302272-A Rev. 00 8-1 Chapter 8Requirements Outside the ISP NetworkAlthough the responsibility for configuring network elements outside the Dial VPN

Seite 9 - 302272-A Rev. 00 ix

Configuring and Troubleshooting Bay Dial VPN Services8-2 302272-A Rev. 00Configuring a Static Route and an Adjacent HostA static route is a manually

Seite 10

Requirements Outside the ISP Network302272-A Rev. 00 8-3 In Figure 8-1, the IP addresses and the frame relay DLCI are in bold type. The dashed lines

Seite 11 - 302272-A Rev. 00 xi

Configuring and Troubleshooting Bay Dial VPN Services8-4 302272-A Rev. 00Dynamic mode lets you make changes to the currently running configuration f

Seite 12

Requirements Outside the ISP Network302272-A Rev. 00 8-5 Configuring the Adjacent Host and Static RoutesThe next step is to create a single adjacent

Seite 13 - 302272-A Rev. 00

302272-A Rev. 00 xiFiguresFigure 1-1. Dial VPN Network with Layer 3 and Layer 2 Tunnels ...1-3Figure 1-2. Dial VPN Networ

Seite 14

Configuring and Troubleshooting Bay Dial VPN Services8-6 302272-A Rev. 00For a Bay Networks router with frame relay, the complete static route is a

Seite 15 - About This Guide

Requirements Outside the ISP Network302272-A Rev. 00 8-7 • The IP address of the CPE router’s network interface to the adjacent host (next hop)• The

Seite 16 - Conventions

Configuring and Troubleshooting Bay Dial VPN Services8-8 302272-A Rev. 00Configuring Frame Relay on the CPE RouterIf the CPE router is a Bay Network

Seite 17 - Acronyms

Requirements Outside the ISP Network302272-A Rev. 00 8-9 • Use the Site Manager Statistics Manager to verify that the frame relay connection is oper

Seite 18

Configuring and Troubleshooting Bay Dial VPN Services8-10 302272-A Rev. 00Configuring the CPE Router for IPX Support (Layer 3 Only)When configuring t

Seite 19 - How to Get Help

Requirements Outside the ISP Network302272-A Rev. 00 8-11 6. Enter the Novell Configured Network Number (in hexadecimal notation) of your Ethernet i

Seite 20

Configuring and Troubleshooting Bay Dial VPN Services8-12 302272-A Rev. 00Table 8-1 shows the relationship between interface types and encapsulation

Seite 21 - Tunneling Overview

Requirements Outside the ISP Network302272-A Rev. 00 8-13 This completes the CPE router Ethernet and Serial interface configuration for IPX.Configur

Seite 22 - What Is Tunneling?

Configuring and Troubleshooting Bay Dial VPN Services8-14 302272-A Rev. 00Enabling L2TP on an Unconfigured WAN InterfaceTo enable L2TP on an unconfig

Seite 23

Requirements Outside the ISP Network302272-A Rev. 00 8-15 Enabling L2TP on an Existing PPP InterfaceTo enable L2TP on an interface with PPP and IP a

Seite 25

Configuring and Troubleshooting Bay Dial VPN Services8-16 302272-A Rev. 00Enabling L2TP on an Existing Frame Relay InterfaceTo enable L2TP on an inte

Seite 26 - DVS0012A

Requirements Outside the ISP Network302272-A Rev. 00 8-17 Installing and Configuring BSAC on the Home NetworkBSAC can run on a server running UNIX,

Seite 27 - Dial VPN Network Components

Configuring and Troubleshooting Bay Dial VPN Services8-18 302272-A Rev. 00Configuring IPX on the Home Network RADIUS ServerBaySecure Access Control (

Seite 28 - 1-8 302272-A Rev. 00

Requirements Outside the ISP Network302272-A Rev. 00 8-19 recognize the gateway address (RADIUS client) and provide addresses from a second subnet.A

Seite 29

Configuring and Troubleshooting Bay Dial VPN Services8-20 302272-A Rev. 00Creating Scopes and a SuperscopeThe following sections describe the procedu

Seite 30 - 1-10 302272-A Rev. 00

Requirements Outside the ISP Network302272-A Rev. 00 8-21 Creating the Scope of Assignable AddressesNext, create the scope of addresses that you wan

Seite 31

Configuring and Troubleshooting Bay Dial VPN Services8-22 302272-A Rev. 00Once you have completed these procedures, the DHCP is configured to dynamic

Seite 32 - 1-12 302272-A Rev. 00

302272-A Rev. 00 9-1 Chapter 9Managing a Dial VPN NetworkManaging a Dial VPN network consists mainly of managing its elements, in particular the Bay

Seite 33

Configuring and Troubleshooting Bay Dial VPN Services9-2 302272-A Rev. 00You must also ensure that remote users have the information they need to di

Seite 34 - Where to Go Next

302272-A Rev. 00 A-1 Appendix APlanning WorksheetThis appendix consists of a network planning worksheet. You may not have enough information yet to

Seite 35 - Dial VPN Layer 2 Tunneling

302272-A Rev. 00xiiiTablesTable 1-1. Layer 3 and Layer 2 Dial VPN Feature Implementation ...1-4Table 4-1. Where to Find Config

Seite 36 - L2T0003A

Configuring and Troubleshooting Bay Dial VPN ServicesA-2 302272-A Rev. 00At the BayDVS Service Provider’s SiteRecord the equipment you have at your o

Seite 37 - 302272-A Rev. 00 2-3

Planning Worksheet302272-A Rev. 00 A-3 • If this is a RADIUS-only configuration, list the IP address of the RADIUS TMS server.(name) _______________

Seite 38 - L2TP Packet Encapsulation

Configuring and Troubleshooting Bay Dial VPN ServicesA-4 302272-A Rev. 00• For the static route between the CPE router and the remote node: -- What i

Seite 39

302272-A Rev. 00 B-1 Appendix BSyslog MessagesThe Remote Access Concentrator and the TMS write system and error messages to the system logfile, sysl

Seite 40 - 2-6 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN ServicesB-2 302272-A Rev. 00Table B-1. Remote Access Concentrator Syslog MessagesType Syslog Contents Me

Seite 41 - Security in an L2TP Network

Syslog Messages302272-A Rev. 00 B-3 Error Messages in this category may include the following <reason> codes:• "Connection timed out"

Seite 42 - 2-8 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN ServicesB-4 302272-A Rev. 00TMS Syslog MessagesWhen an error occurs in the embedded code or TMS portion

Seite 43 - RADIUS User Authentication

Syslog Messages302272-A Rev. 00 B-5 Table B-2. TMS Syslog MessagesType Message MeaningWarning tms: could not parse request from <NAS_IP_address&

Seite 44 - L2TP IP Interface Addresses

Configuring and Troubleshooting Bay Dial VPN ServicesB-6 302272-A Rev. 00Critical tms: RAS database not found This is a serious problem indicating th

Seite 45 - Starting an L2TP Session

Syslog Messages302272-A Rev. 00 B-7 Notice tms: <domain/DNIS> RAS <NAS_IP_address> count already zeroThis message indicates a correction

Seite 47 - 302272-A Rev. 00 2-13

Configuring and Troubleshooting Bay Dial VPN ServicesB-8 302272-A Rev. 00Error Messages in this category may include the following <reason> cod

Seite 48 - 2-14 302272-A Rev. 00

Syslog Messages302272-A Rev. 00 B-9 Error(continued)ppp:<port#>:DVS:tunnel registration failed: <reason>An error occurred during the tun

Seite 50 - DVS0001A

302272-A Rev. 00 C-1 Appendix CTroubleshootingThis chapter assumes that you have a working knowledge of Site Manager and the Remote Access Concentra

Seite 51 - 302272-A Rev. 00 3-3

Configuring and Troubleshooting Bay Dial VPN ServicesC-2 302272-A Rev. 00Preventing ProblemsThe suggestions that follow can help you anticipate and

Seite 52 - How Tunnel Management Works

Troubleshooting302272-A Rev. 00 C-3 5.Back up your files.Store backup copies of the configuration files on the Site Manager workstation. Use a log t

Seite 53

Configuring and Troubleshooting Bay Dial VPN ServicesC-4 302272-A Rev. 00Troubleshooting WorksheetThis section poses the initial questions you shoul

Seite 54 - How the TMS Database Works

Troubleshooting302272-A Rev. 00 C-5 4.Are you using a workaround to prevent the symptoms from occurring? If so, what?_______________________________

Seite 55 - How DHCP Works

Configuring and Troubleshooting Bay Dial VPN ServicesC-6 302272-A Rev. 00Table C-1. Problem Symptoms and Likely CausesIf the symptoms are limited t

Seite 56 - shows the entire process

Troubleshooting302272-A Rev. 00 C-7 Using the System Logs (syslogs) to Diagnose ProblemsThe Remote Access Concentrator provides two mechanisms for l

Seite 57

302272-A Rev. 00 xv About This GuideIf you are responsible for configuring Bay Dial Virtual Private Network (VPN) services on your network, you need

Seite 58 - Assigning Addresses

Configuring and Troubleshooting Bay Dial VPN ServicesC-8 302272-A Rev. 00• Displaying RAC statistics• Monitoring serial line activityYou can display

Seite 59

Troubleshooting302272-A Rev. 00 C-9 If a software entity experiences a fault and fails to recover:a.Disable and reenable the port.Watch the event lo

Seite 60 - Starting the Connection

Configuring and Troubleshooting Bay Dial VPN ServicesC-10 302272-A Rev. 003.Display and change configuration settings and statistics.You can use the

Seite 61

Troubleshooting302272-A Rev. 00 C-11 • Screen Builder - Lets you build windows of statistics from scratch or customize statistics windows you copied

Seite 62 - 3-14 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN ServicesC-12 302272-A Rev. 005.Display the encapsulated packet statistics using the netstat - s command.

Seite 63

Troubleshooting302272-A Rev. 00 C-13 7.Use Packet Capture to save data packets for later analysis.The Technician Interface Packet Capture tool allow

Seite 64 - 3-16 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN ServicesC-14 302272-A Rev. 009.Document each step you do in the troubleshooting process.An effective tro

Seite 65

Troubleshooting302272-A Rev. 00 C-15 Troubleshooting Specific ProtocolsRead the following section if you have isolated the problem to a network prot

Seite 66 - DVS0007A

Configuring and Troubleshooting Bay Dial VPN ServicesC-16 302272-A Rev. 00Table C-2. Remote Access Concentrator Troubleshooting ChartProblem/Symptom

Seite 67

Troubleshooting302272-A Rev. 00 C-17 Hosts don’t appear in hosts display.The Remote Access Concentrator hosts command should list any hosts that bro

Seite 68

Configuring and Troubleshooting Bay Dial VPN Servicesxvi 302272-A Rev. 00Conventionsangle brackets (< >) Indicate that you choose the text to

Seite 69 - Chapter 4

Configuring and Troubleshooting Bay Dial VPN ServicesC-18 302272-A Rev. 00Network logins to BSD hosts are invisible.The Remote Access Concentrator us

Seite 70 - 4-2 302272-A Rev. 00

Troubleshooting302272-A Rev. 00 C-19 Remote Access Concentrator does not advertise updates.1. Is the RAC parameter routed set to N?2. Did you reboot

Seite 71 - <acp or RADIUS>

Configuring and Troubleshooting Bay Dial VPN ServicesC-20 302272-A Rev. 00Remote Access Concentrator does not advertise updates.(continued)6. If your

Seite 72 - 4-4 302272-A Rev. 00

Troubleshooting302272-A Rev. 00 C-21 RAC does not receive updates.1. Are the routes really being advertised?Check whether other routers on the netwo

Seite 73 - 302272-A Rev. 00 4-5

Configuring and Troubleshooting Bay Dial VPN ServicesC-22 302272-A Rev. 00Tracing a Packet’s Path at the Remote Access ConcentratorYou can use the pi

Seite 74 - 4-6 302272-A Rev. 00

Troubleshooting302272-A Rev. 00 C-23 Figure C-4. Network Topology for ping -t ExamplesGiven the topology in Figure 4, the command:annex# ping –t 13

Seite 75 - Configuring Active RIP

Configuring and Troubleshooting Bay Dial VPN ServicesC-24 302272-A Rev. 00• Equipment failure• Configuration errors• TMS database errorsUser errors,

Seite 76

Troubleshooting302272-A Rev. 00 C-25 Troubleshooting the LACIn this example, the host ‘vega’ was configured as the syslog host for the LAC, or 5399.

Seite 77 - Chapter 5

Configuring and Troubleshooting Bay Dial VPN ServicesC-26 302272-A Rev. 00Mar 16 15:26:32 bay_lac ppp[1321]: ppp:asy23:l2tp tunnel call established,

Seite 78

Troubleshooting302272-A Rev. 00 C-27 # 1: 03/16/98 14:51:30.804 INFO SLOT 3 L2TP Code: 4L2TP LNS IP Address 132.245.56.6

Seite 79

About This Guide302272-A Rev. 00 xvii AcronymsACP Access Control ProtocolBRI Basic Rate InterfaceCHAP Challenge Handshake Authentication ProtocolCLI

Seite 80 - Tunnel Management Commands

Configuring and Troubleshooting Bay Dial VPN ServicesC-28 302272-A Rev. 00# 8: 03/16/98 15:32:27.152 INFO SLOT 3 RADIUS Code:

Seite 81 - Command Arguments

Troubleshooting302272-A Rev. 00 C-29 RADIUS Accounting Response received for id 1 # 22: 03/16/98 15:32:27.593 TRACE SLOT 3 PPP Code: 5

Seite 82

Configuring and Troubleshooting Bay Dial VPN ServicesC-30 302272-A Rev. 00[2:1]$ show l2tp statL2TP Statistics---------------Slot: 3 SCCRQ

Seite 83

Troubleshooting302272-A Rev. 00 C-31 None65534Up 10.10.10.254255.255.255.0E21 1 Up10.250.20.1255.255.255.0S31 2 U

Seite 84

Configuring and Troubleshooting Bay Dial VPN ServicesC-32 302272-A Rev. 00In this example, at 15:36:31 the user [email protected] was successfully auth

Seite 85

302272-A Rev. 00 Glossary-1 GlossaryAccess Control Protocol (ACP)Bay Networks software utility that provides a wide range of security features to A

Seite 86

Configuring and Troubleshooting Bay Dial VPN ServicesGlossary-2 302272-A Rev. 00decapsulationStripping protocol-specific information from a data pack

Seite 87

Glossary302272-A Rev. 00 Glossary-3 Internet Protocol (IP)Part of the TCP/IP suite of protocols defined in RFC 791. Describes the software responsib

Seite 88 - 0013ABC0:001234560000

Configuring and Troubleshooting Bay Dial VPN ServicesGlossary-4 302272-A Rev. 00NCPNetwork Control Protocol. Software that manages the traffic betwee

Seite 89 - Chapter 6

Glossary302272-A Rev. 00 Glossary-5 RIPRouting Information Protocol. A distance-vector protocol in the IP suite (used by IP and IPX network-layer pr

Seite 90 - 6-2 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN Servicesxviii 302272-A Rev. 00PSTN public-switched telephone networkPVC permanent virtual circuitRADIUS

Seite 91 - DVS0015A

Configuring and Troubleshooting Bay Dial VPN ServicesGlossary-6 302272-A Rev. 00Tunnel Management System (TMS)A database of IP tunnel management info

Seite 92 - Using RADIUS Accounting

302272-A Rev. 00Index-1AAccess Control Protocol log file, C-7Access Control Protocol server, 1-10Access Stack Node (ASN), 1-2accountinggateway and tun

Seite 93 - RADIUS server

Index-2302272-A Rev. 00configuringadjacent host, 8-6adjacent host and static route, 8-2Dial VPN, 1-7Remote Annex software, 4-1static route, 8-7congest

Seite 94

302272-A Rev. 00Index-3Events Manager, C-8Expedited Remote Procedure Call Daemon. See erpcdFfault event, C-8, C-9forwarding tables, saving, C-13Frame

Seite 95

Index-4302272-A Rev. 00layer 2 tunnel end point, configuring, 8-13LED indicators, C-5list tms_dbm command, 5-4LNSBay Networks implementation, 2-5confi

Seite 96

302272-A Rev. 00Index-5primary secret, 8-1primary_accounting_server_addr, TMS parameter, 5-8primary_authentication_ server_addr, TMS parameter, 5-8pri

Seite 97

Index-6302272-A Rev. 00secondary_accounting_server_addr, TMS parameter, 5-8secondary_authentication_server_addr, TMS parameter, 5-8secondary_dynamic_a

Seite 98

302272-A Rev. 00Index-7TMS syslog messages, B-5TMS, description, 1-10, 1-11, 2-6tms_dbm command arguments, 5-5tms_dbm commands, 5-4tool, configuration

Seite 100 - 7-2 302272-A Rev. 00

About This Guide302272-A Rev. 00 xix Bay Networks Customer ServiceYou can purchase a support contract from your Bay Networks distributor or authoriz

Seite 101 - 302272-A Rev. 00 7-3

ii302272-A Rev. 004401 Great America Parkway 8 Federal StreetSanta Clara, CA 95054 Billerica, MA 01821Copyright © 1998 Bay Networks, Inc.All rights re

Seite 102 - 7-4 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN Servicesxx 302272-A Rev. 00Bay Networks Educational ServicesThrough Bay Networks Educational Services, y

Seite 103 - Gateway Accounting Messages

302272-A Rev. 00 1-1 Chapter 1Tunneling OverviewBay Networks Dial Virtual Private Network Services provides secure dial-access services for corporat

Seite 104

Configuring and Troubleshooting Bay Dial VPN Services1-2 302272-A Rev. 00Dial VPN encapsulates multiprotocol data within an IP datagram. It then sen

Seite 105 - Chapter 8

Tunneling Overview302272-A Rev. 00 1-3 Dial VPN dynamically creates a tunnel when it connects to the remote node’s home network. One end point of th

Seite 106 - 8-2 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN Services1-4 302272-A Rev. 00Layer 3 TunnelingIn Layer 3 tunneling, the tunnel exists between the Networ

Seite 107 - 302272-A Rev. 00 8-3

Tunneling Overview302272-A Rev. 00 1-5 How a Dial VPN Network FunctionsAny authorized remote user (using a PC or dial-up router) who has access to a

Seite 108 - (continued)

Configuring and Troubleshooting Bay Dial VPN Services1-6 302272-A Rev. 00Figure 1-2. Dial VPN Network with Connections to Different Destination Type

Seite 109

Tunneling Overview302272-A Rev. 00 1-7 For Bay Networks routers used with a Layer 3 Dial VPN tunnel, you must specify an adjacent host and a static

Seite 110

Configuring and Troubleshooting Bay Dial VPN Services1-8 302272-A Rev. 00The following considerations apply only to Layer 2 (L2TP) tunnels:• If the

Seite 111 - 302272-A Rev. 00 8-7

Tunneling Overview302272-A Rev. 00 1-9 GatewayUsed only in Layer 3 networks, the gateway can be an ASN, BLN, BLN-2, BCN, or System 5000 MSX equipped

Seite 112 - 8-8 302272-A Rev. 00

302272-A Rev. 00 iiiBay Networks, Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using the acc

Seite 113 - 302272-A Rev. 00 8-9

Configuring and Troubleshooting Bay Dial VPN Services1-10 302272-A Rev. 00Tunnel Management Server (TMS)The mechanism for identifying tunneled users

Seite 114

Tunneling Overview302272-A Rev. 00 1-11 L2TP Access Concentrator (LAC)The L2TP access concentrator (LAC) resides at the ISP network. The LAC establi

Seite 115

Configuring and Troubleshooting Bay Dial VPN Services1-12 302272-A Rev. 00Enterprise subscribers of this service must configure the CPE router to all

Seite 116

Tunneling Overview302272-A Rev. 00 1-13 • Providing accounting services for corporate billingFor Layer 3 tunnels, the RADIUS client of this server r

Seite 117 - Enabling L2TP

Configuring and Troubleshooting Bay Dial VPN Services1-14 302272-A Rev. 00DHCP ServerIf you implement the optional Dynamic Host Configuration Protoco

Seite 118 - Configuration is completed

302272-A Rev. 00 2-1 Chapter 2Dial VPN Layer 2 TunnelingThis chapter describes how a Layer2 Dial VPN tunnel functions. Among these concepts are how

Seite 119

Configuring and Troubleshooting Bay Dial VPN Services2-2 302272-A Rev. 00Figure 2-1. Layer 2 Tunnel Packet PathBuilding a Network for Layer 2 Tunnel

Seite 120

Dial VPN Layer 2 Tunneling302272-A Rev. 00 2-3 2.Install and configure any intermediate nodes on the WAN.The WAN can include intermediate nodes. For

Seite 121 - (continued)

Configuring and Troubleshooting Bay Dial VPN Services2-4 302272-A Rev. 00• The CPE router that is the end point of Layer 2 tunnels is configured as

Seite 122 - 8-18 302272-A Rev. 00

Dial VPN Layer 2 Tunneling302272-A Rev. 00 2-5 Figure 2-2. L2TP Packet Encapsulation ProcessBay Networks L2TP ImplementationIn an L2TP tunnel, the B

Seite 123 - field, which by

iv 302272-A Rev. 00its own data and information and for maintaining adequate procedures apart from the Software to reconstruct lost or altered files,

Seite 124

Configuring and Troubleshooting Bay Dial VPN Services2-6 302272-A Rev. 00• The LNS performs user authentication with a RADIUS server to prevent unau

Seite 125 - Creating a Superscope

Dial VPN Layer 2 Tunneling302272-A Rev. 00 2-7 When the LAC receives a call, it forwards the domain name to the TMS. The domain name is the portion

Seite 126

Configuring and Troubleshooting Bay Dial VPN Services2-8 302272-A Rev. 00During tunnel authentication, the LNS identifies the L2TP client or LAC by

Seite 127 - Managing a Dial VPN Network

Dial VPN Layer 2 Tunneling302272-A Rev. 00 2-9 Figure 2-3. Tunnel Authentication Control MessagesAfter tunnel authentication is complete, it need no

Seite 128 - 9-2 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN Services2-10 302272-A Rev. 00RADIUS AccountingThe RADIUS server can provide accounting services in addit

Seite 129 - Planning Worksheet

Dial VPN Layer 2 Tunneling302272-A Rev. 00 2-11 Remote Router ConfigurationIf the host at the remote site is a Bay Networks router, you may need to

Seite 130 - A-2 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN Services2-12 302272-A Rev. 00Examples of L2TP TunnelsFigure 2-4 shows an L2TP network that uses a LAC to

Seite 131 - For Each Destination Site

Dial VPN Layer 2 Tunneling302272-A Rev. 00 2-13 Making a Connection Across an L2TP NetworkThe following steps explain how a remote user connects acr

Seite 132 - For Each Remote Node

Configuring and Troubleshooting Bay Dial VPN Services2-14 302272-A Rev. 00When Does Dial VPN Tear Down the Tunnel?The LAC brings down the tunnel for

Seite 133 - Syslog Messages

302272-A Rev. 00 3-1 Chapter 3Dial VPN Layer 3 TunnelingThis chapter describes how a Layer 3 Dial VPN tunnel functions. Among these concepts are how

Seite 134

302272-A Rev. 00 vContents About This GuideBefore You Begin ...

Seite 135

Configuring and Troubleshooting Bay Dial VPN Services3-2 302272-A Rev. 00Figure 3-1. Layer 3 Tunnel Packet PathBuilding a Network for Layer 3 Tunnel

Seite 136 - TMS Syslog Messages

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-3 3.Install the software for the tunnel management server, Remote Access Concentrator, and (for the erp

Seite 137

Configuring and Troubleshooting Bay Dial VPN Services3-4 302272-A Rev. 0010.Make sure that the home network is configured to connect to the Dial VPN

Seite 138

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-5 The Grant message contains the following information, which is stored in the TMS database:• Remote no

Seite 139

Configuring and Troubleshooting Bay Dial VPN Services3-6 302272-A Rev. 00How the TMS Database WorksThe TMS database (by default, UNIX ndbm) resides

Seite 140

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-7 Using DHCP for Dynamic IP Address AllocationThis method requires a DHCP server on the home/corporate

Seite 141

Configuring and Troubleshooting Bay Dial VPN Services3-8 302272-A Rev. 00DHCP discover request to the DHCP server on the home network, and the serve

Seite 142

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-9 Using RADIUS for Dynamic IP Address AllocationEach dial-in user retains exclusive uses of a unique IP

Seite 143 - Troubleshooting

Configuring and Troubleshooting Bay Dial VPN Services3-10 302272-A Rev. 00The BSAC (RADIUS) administrator at the customer’s site must enter one or mo

Seite 144 - Preventing Problems

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-11 Figure 3-3. Dial VPN Dynamic IP Address Management SequenceAt the start of service delivery, a clien

Seite 145 - Preparing to Troubleshoot

vi 302272-A Rev. 00L2TP Network Server (LNS) ...1-12RADIUS Authentication Se

Seite 146 - Troubleshooting Worksheet

Configuring and Troubleshooting Bay Dial VPN Services3-12 302272-A Rev. 00the end of service delivery, the client sends the RADIUS server a Stop pack

Seite 147 - 302272-A Rev. 00 C-5

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-13 If the TMS finds a match in its database for both the user and domain names, it determines that this

Seite 148 - Cable Guide

Configuring and Troubleshooting Bay Dial VPN Services3-14 302272-A Rev. 00If the home network is configured to assign IP addresses dynamically using

Seite 149

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-15 Figure 3-4. Packet Encapsulation and Decapsulation ProcessFlag FlagAddress Control Protocol Data FC

Seite 150 - C-8 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN Services3-16 302272-A Rev. 00How a Packet Moves Through a Dial VPN NetworkA data packet moves from a rem

Seite 151 - Caution: Avoid using the

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-17 5.The CPE router decapsulates the frame relay or PPP packet and routes the data to the intended reci

Seite 152 - Caution:

Configuring and Troubleshooting Bay Dial VPN Services3-18 302272-A Rev. 00The data packet travels from the home network to the remote node using a si

Seite 153 - 302272-A Rev. 00 C-11

Dial VPN Layer 3 Tunneling302272-A Rev. 00 3-19 When Does Dial VPN Tear Down the Tunnel?Dial VPN tears down the tunnel when any of the following sit

Seite 155 - 302272-A Rev. 00 C-13

302272-A Rev. 00 4-1 Chapter 4Configuring the Remote Access ConcentratorThis chapter describes how to use the command line interface (CLI) commands

Seite 156 - C-14 302272-A Rev. 00

302272-A Rev. 00 viiAssigning Addresses ...3-10Starting the

Seite 157

Configuring and Troubleshooting Bay Dial VPN Services4-2 302272-A Rev. 001.Install the RAC software.Use the installation script supplied for the RAC

Seite 158

Configuring the Remote Access Concentrator302272-A Rev. 00 4-3 ## If running IPX (Layer 3 only), include the following command.set port ppp_ncp all#

Seite 159

Configuring and Troubleshooting Bay Dial VPN Services4-4 302272-A Rev. 004.Enable the appropriate options.To display the options that are enabled, u

Seite 160

Configuring the Remote Access Concentrator302272-A Rev. 00 4-5 called_no <called number>call_action v.120set mode auto_detectend_session#begin

Seite 161 - Using Command Line Interfaces

Configuring and Troubleshooting Bay Dial VPN Services4-6 302272-A Rev. 00For a default route, the syntax is: route add <default><next_hop&g

Seite 162

Configuring the Remote Access Concentrator302272-A Rev. 00 4-7 During the initial boot of the operational code, the ROM monitor requires the address

Seite 163 - Command Line Interfaces

Configuring and Troubleshooting Bay Dial VPN Services4-8 302272-A Rev. 00Configuring the RAC to Advertise RIP 1 and/or RIP 2 UpdatesBy default, acti

Seite 164 - C-22 302272-A Rev. 00

302272-A Rev. 00 5-1 Chapter 5Configuring TMS and Security for erpcd NetworksIn a Dial VPN network, tunnel users are authenticated by a RADIUS serve

Seite 165 - DVS0005A

Configuring and Troubleshooting Bay Dial VPN Services5-2 302272-A Rev. 00Managing TMS Using the TMS Default DatabaseTunnel management in an erpcd-ba

Seite 166 - C-24 302272-A Rev. 00

Configuring TMS and Security for erpcd Networks302272-A Rev. 00 5-3 sauth=<ip addr of secondary authentication server>\[pacct=<ip addr of p

Seite 167 - Troubleshooting the LAC

viii 302272-A Rev. 00Chapter 7 Configuring the Layer 3 GatewayConfiguring the Gateway ...

Seite 168 - Troubleshooting the LNS

Configuring and Troubleshooting Bay Dial VPN Services5-4 302272-A Rev. 00Using Tunnel Management CommandsThe following sections describe the syntax

Seite 169

Configuring TMS and Security for erpcd Networks302272-A Rev. 00 5-5 All commands except add and help return an error if the entry is not found.Comma

Seite 170

Configuring and Troubleshooting Bay Dial VPN Services5-6 302272-A Rev. 00te=te_addrSpecifies the IP address of the frame relay port on the gateway o

Seite 171

Configuring TMS and Security for erpcd Networks302272-A Rev. 00 5-7 hwtype=hw_typehwaddr=hw_addrhwalen=hw_addr_lenhwtype indicates the type of netwo

Seite 172

Configuring and Troubleshooting Bay Dial VPN Services5-8 302272-A Rev. 00tutype=tunnel_typeSpecifies the type of tunnel to establish. For a Layer 3

Seite 173

Configuring TMS and Security for erpcd Networks302272-A Rev. 00 5-9 acctp=accounting_protocolSpecifies the accounting protocol used between the gate

Seite 174 - C-32 302272-A Rev. 00

Configuring and Troubleshooting Bay Dial VPN Services5-10 302272-A Rev. 00passwd=passwordRelevant only for Layer 2 tunnels, this parameter specifies

Seite 175 - Glossary

Configuring TMS and Security for erpcd Networks302272-A Rev. 00 5-11 Configuring Local Authentication Using the ACPDial VPN relies on the remote aut

Seite 176

Configuring and Troubleshooting Bay Dial VPN Services5-12 302272-A Rev. 00For IPX, use the network and node address combination; for example:0013ABC0

Seite 177

302272-A Rev. 00 6-1 Chapter 6Configuring the TMS Using Local RADIUSYou can configure the TMS database to use a RADIUS server on the service provide

Seite 178

302272-A Rev. 00 ixAppendix A Planning WorksheetBayDVS Network Planning Worksheet ...

Seite 179

Configuring and Troubleshooting Bay Dial VPN Services6-2 302272-A Rev. 00The NAS uses RADIUS accounting messages to determine when the TMS tunnel to

Seite 180 - Network (VPN)

Configuring the TMS Using Local RADIUS302272-A Rev. 00 6-3 Figure 6-1. Message Exchanges Supporting RADIUS TMS OperationsLCP negotiateCHAP initiatio

Seite 181

Configuring and Troubleshooting Bay Dial VPN Services6-4 302272-A Rev. 00Using RADIUS AccountingThe NAS logs the tunnel-bound link sessions to the s

Seite 182

Configuring the TMS Using Local RADIUS302272-A Rev. 00 6-5 Table 6-2 summarizes the user stop messages that the NAS sends to the provider’s RADIUS s

Seite 183

Configuring and Troubleshooting Bay Dial VPN Services6-6 302272-A Rev. 00RADIUS Attributes That Support TunnelingThe RADIUS attributes that support

Seite 184

Configuring the TMS Using Local RADIUS302272-A Rev. 00 6-7 Table 6-4 lists the RADIUS attributes that the Layer 3 gateway supports.Table 6-4. RADIUS

Seite 185

Configuring and Troubleshooting Bay Dial VPN Services6-8 302272-A Rev. 00TMS Parameters for erpcd-based and All-RADIUS Tunnels While TMS operation i

Seite 186

Configuring the TMS Using Local RADIUS302272-A Rev. 00 6-9 TMS System Log (Syslog) MessagesTMS writes its system and error messages to the system lo

Seite 188

302272-A Rev. 00 7-1 Chapter 7Configuring the Layer 3 GatewayOnly Layer 3 tunnels use a gateway. To configure a Bay Networks router at the service p

Kommentare zu diesen Handbüchern

Keine Kommentare