Avaya Configuring and Troubleshooting Bay Dial VPN (DVS) Networks Manual de usuario

Busca en linea o descarga Manual de usuario para Software Avaya Configuring and Troubleshooting Bay Dial VPN (DVS) Networks. Avaya Configuring and Troubleshooting Bay Dial VPN (DVS) Networks User's Manual [ua] Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 190
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente

Indice de contenidos

Pagina 1 - VPN Services

Part No. 303509-A Rev 00October 1998BayRS Version 13.00Site Manager Software Version 7.00 Configuring and Troubleshooting Bay Dial VPN Services

Pagina 4

303509-A Rev 00 7-1 Chapter 7Configuring the Layer 3 GatewayOnly Layer 3 tunnels use a gateway. To configure a Bay Networks router at the service pr

Pagina 5 - Contents

Configuring and Troubleshooting Bay Dial VPN Services7-2 303509-A Rev 005.Specify the IP address for this frame relay or PPP interface.This is the “

Pagina 6

Configuring the Layer 3 Gateway303509-A Rev 00 7-3 c.Specify the keys associated with this SPI value.Each SPI value has a 128-bit key associated wit

Pagina 7 - 303509-A Rev 00 vii

Configuring and Troubleshooting Bay Dial VPN Services7-4 303509-A Rev 00h.Enter the IP address of the RADIUS server to which this client will connec

Pagina 8

Configuring the Layer 3 Gateway303509-A Rev 00 7-5 d.Specify the address of one or more DHCP servers on the home nework.Refer to Chapter 8 for addit

Pagina 10

303509-A Rev 00 8-1 Chapter 8Requirements Outside the ISP NetworkAlthough the responsibility for configuring network elements outside the Dial VPN s

Pagina 11 - 303509-A Rev 00 xi

Configuring and Troubleshooting Bay Dial VPN Services8-2 303509-A Rev 00Configuring a Static Route and an Adjacent HostA static route is a manually

Pagina 12

Requirements Outside the ISP Network303509-A Rev 00 8-3 In Figure 8-1, the IP addresses and the frame relay DLCI are in bold type. The dashed lines

Pagina 13 - 303509-A Rev 00

303509-A Rev 00 xiFiguresFigure 1-1. Dial VPN Network with Layer 3 and Layer 2 Tunnels ...1-3Figure 1-2. Dial VPN Network

Pagina 14

Configuring and Troubleshooting Bay Dial VPN Services8-4 303509-A Rev 00Dynamic mode lets you make changes to the currently running configuration fi

Pagina 15 - Text Conventions

Requirements Outside the ISP Network303509-A Rev 00 8-5 Configuring the Adjacent Host and Static RoutesThe next step is to create a single adjacent

Pagina 16

Configuring and Troubleshooting Bay Dial VPN Services8-6 303509-A Rev 00For a Bay Networks router with frame relay, the complete static route is a c

Pagina 17 - Acronyms

Requirements Outside the ISP Network303509-A Rev 00 8-7 • The IP address of the CPE router’s network interface to the adjacent host (next hop)• The

Pagina 18

Configuring and Troubleshooting Bay Dial VPN Services8-8 303509-A Rev 00Configuring Frame Relay on the CPE RouterIf the CPE router is a Bay Networks

Pagina 19 - How to Get Help

Requirements Outside the ISP Network303509-A Rev 00 8-9 • Use the Site Manager Statistics Manager to verify that the frame relay connection is opera

Pagina 20

Configuring and Troubleshooting Bay Dial VPN Services8-10 303509-A Rev 00Configuring the CPE Router for IPX Support (Layer 3 Only)When configuring t

Pagina 21 - Tunneling Overview

Requirements Outside the ISP Network303509-A Rev 00 8-11 6. Enter the Novell Configured Network Number (in hexadecimal notation) of your Ethernet in

Pagina 22 - What Is Tunneling?

Configuring and Troubleshooting Bay Dial VPN Services8-12 303509-A Rev 00Table 8-1 shows the relationship between interface types and encapsulation

Pagina 23

Requirements Outside the ISP Network303509-A Rev 00 8-13 This completes the CPE router Ethernet and Serial interface configuration for IPX.Configuri

Pagina 25

Configuring and Troubleshooting Bay Dial VPN Services8-14 303509-A Rev 00Enabling L2TP on an Unconfigured WAN InterfaceTo enable L2TP on an unconfig

Pagina 26 - 1-6 303509-A Rev 00

Requirements Outside the ISP Network303509-A Rev 00 8-15 Enabling L2TP on an Existing PPP InterfaceTo enable L2TP on an interface with PPP and IP al

Pagina 27 - Dial VPN Network Components

Configuring and Troubleshooting Bay Dial VPN Services8-16 303509-A Rev 00Enabling L2TP on an Existing Frame Relay InterfaceTo enable L2TP on an inte

Pagina 28 - 1-8 303509-A Rev 00

Requirements Outside the ISP Network303509-A Rev 00 8-17 Installing and Configuring BSAC on the Home NetworkBSAC can run on a server running UNIX, N

Pagina 29

Configuring and Troubleshooting Bay Dial VPN Services8-18 303509-A Rev 00Configuring IPX on the Home Network RADIUS ServerBaySecure Access Control (

Pagina 30 - 1-10 303509-A Rev 00

Requirements Outside the ISP Network303509-A Rev 00 8-19 recognize the gateway address (RADIUS client) and provide addresses from a second subnet.A

Pagina 31

Configuring and Troubleshooting Bay Dial VPN Services8-20 303509-A Rev 00Creating Scopes and a SuperscopeThe following sections describe the procedu

Pagina 32 - 1-12 303509-A Rev 00

Requirements Outside the ISP Network303509-A Rev 00 8-21 Creating the Scope of Assignable AddressesNext, create the scope of addresses that you want

Pagina 33

Configuring and Troubleshooting Bay Dial VPN Services8-22 303509-A Rev 00Once you have completed these procedures, the DHCP is configured to dynamic

Pagina 34 - Where to Go Next

303509-A Rev 00 9-1 Chapter 9Managing a Dial VPN NetworkManaging a Dial VPN network consists mainly of managing its elements, in particular the Bay

Pagina 35 - Dial VPN Layer 2 Tunneling

303509-A Rev 00xiiiTablesTable 1-1. Layer 3 and Layer 2 Dial VPN Feature Implementation ...1-5Table 4-1. Where to Find Configu

Pagina 36 - L2T0003A

Configuring and Troubleshooting Bay Dial VPN Services9-2 303509-A Rev 00You must also ensure that remote users have the information they need to dia

Pagina 37 - 303509-A Rev 00 2-3

303509-A Rev 00 A-1 Appendix APlanning WorksheetThis appendix consists of a network planning worksheet. You may not have enough information yet to c

Pagina 38 - L2TP Packet Encapsulation

Configuring and Troubleshooting Bay Dial VPN ServicesA-2 303509-A Rev 00At the BayDVS Service Provider’s SiteRecord the equipment you have at your o

Pagina 39

Planning Worksheet303509-A Rev 00 A-3 • If this is a RADIUS-only configuration, list the IP address of the RADIUS TMS server.(name) ________________

Pagina 40 - 2-6 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN ServicesA-4 303509-A Rev 00• For the static route between the CPE router and the remote node: -- What i

Pagina 41 - Security in an L2TP Network

303509-A Rev 00 B-1 Appendix BSyslog MessagesThe Remote Access Concentrator and the TMS write system and error messages to the system logfile, syslo

Pagina 42 - 2-8 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN ServicesB-2 303509-A Rev 00Table B-1. Remote Access Concentrator Syslog MessagesType Syslog Contents Me

Pagina 43 - RADIUS User Authentication

Syslog Messages303509-A Rev 00 B-3 Error Messages in this category may include the following <reason> codes:• "Connection timed out"

Pagina 44 - L2TP IP Interface Addresses

Configuring and Troubleshooting Bay Dial VPN ServicesB-4 303509-A Rev 00TMS Syslog MessagesWhen an error occurs in the embedded code or TMS portion

Pagina 45 - Starting an L2TP Session

Syslog Messages303509-A Rev 00 B-5 Table B-2. TMS Syslog MessagesType Message MeaningWarning tms: could not parse request from <NAS_IP_address&g

Pagina 47 - 303509-A Rev 00 2-13

Configuring and Troubleshooting Bay Dial VPN ServicesB-6 303509-A Rev 00Critical tms: RAS database not found This is a serious problem indicating th

Pagina 48 - 2-14 303509-A Rev 00

Syslog Messages303509-A Rev 00 B-7 Notice tms: <domain/DNIS> RAS <NAS_IP_address> count already zeroThis message indicates a correction,

Pagina 49 - Dial VPN Layer 3 Tunneling

Configuring and Troubleshooting Bay Dial VPN ServicesB-8 303509-A Rev 00Error Messages in this category may include the following <reason> cod

Pagina 50 - 3-2 303509-A Rev 00

Syslog Messages303509-A Rev 00 B-9 Error(continued)ppp:<port#>:DVS:tunnel registration failed: <reason>An error occurred during the tunn

Pagina 52 - How Tunnel Management Works

303509-A Rev 00 C-1 Appendix CTroubleshootingThis appendix assumes that you have a working knowledge of Site Manager and the Remote Access Concentra

Pagina 53

Configuring and Troubleshooting Bay Dial VPN ServicesC-2 303509-A Rev 00Preventing ProblemsThe suggestions that follow can help you anticipate and p

Pagina 54 - How the TMS Database Works

Troubleshooting303509-A Rev 00 C-3 5.Back up your files.Store backup copies of the configuration files on the Site Manager workstation. Use a log to

Pagina 55 - How DHCP Works

Configuring and Troubleshooting Bay Dial VPN ServicesC-4 303509-A Rev 00Troubleshooting WorksheetThis section poses the initial questions you should

Pagina 56 - shows the entire process

Troubleshooting303509-A Rev 00 C-5 4.Are you using a workaround to prevent the symptoms from occurring? If so, what?________________________________

Pagina 57

303509-A Rev 00xv PrefaceThis guide describes Bay Networks Dial Virtual Private Network (VPN) and what you do to start and customize Bay Dial VPN serv

Pagina 58 - Assigning Addresses

Configuring and Troubleshooting Bay Dial VPN ServicesC-6 303509-A Rev 00Table C-1. Problem Symptoms and Likely CausesIf the symptoms are limited to

Pagina 59

Troubleshooting303509-A Rev 00 C-7 Using the System Logs (syslogs) to Diagnose ProblemsThe Remote Access Concentrator provides two mechanisms for lo

Pagina 60 - Starting the Connection

Configuring and Troubleshooting Bay Dial VPN ServicesC-8 303509-A Rev 00• Displaying RAC statistics• Monitoring serial line activityYou can display

Pagina 61

Troubleshooting303509-A Rev 00 C-9 If a software entity experiences a fault and fails to recover:a.Disable and reenable the port.Watch the event log

Pagina 62 - 3-14 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN ServicesC-10 303509-A Rev 003.Display and change configuration settings and statistics.You can use the

Pagina 63

Troubleshooting303509-A Rev 00 C-11 • Screen Builder - Lets you build windows of statistics from scratch or customize statistics windows you copied

Pagina 64 - 3-16 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN ServicesC-12 303509-A Rev 005.Display the encapsulated packet statistics using the netstat - s command.

Pagina 65

Troubleshooting303509-A Rev 00 C-13 7.Use Packet Capture to save data packets for later analysis.The Technician Interface Packet Capture tool allows

Pagina 66 - DVS0007A

Configuring and Troubleshooting Bay Dial VPN ServicesC-14 303509-A Rev 009.Document each step you do in the troubleshooting process.An effective tro

Pagina 67

Troubleshooting303509-A Rev 00 C-15 Troubleshooting Specific ProtocolsRead the following section if you have isolated the problem to a network proto

Pagina 68

Configuring and Troubleshooting Bay Dial VPN Servicesxvi303509-A Rev 00braces ({}) Indicate required elements in syntax descriptions where there is mo

Pagina 69 - Chapter 4

Configuring and Troubleshooting Bay Dial VPN ServicesC-16 303509-A Rev 00Table C-2. Remote Access Concentrator Troubleshooting ChartProblem/Symptom

Pagina 70 - 4-2 303509-A Rev 00

Troubleshooting303509-A Rev 00 C-17 Hosts don’t appear in hosts display.The Remote Access Concentrator hosts command should list any hosts that broa

Pagina 71 - <acp_or_RADIUS>

Configuring and Troubleshooting Bay Dial VPN ServicesC-18 303509-A Rev 00Network logins to BSD hosts are invisible.The Remote Access Concentrator us

Pagina 72 - stats -o

Troubleshooting303509-A Rev 00 C-19 Remote Access Concentrator does not advertise updates.1. Is the RAC parameter routed set to N?2. Did you reboot

Pagina 73 - <called_number>

Configuring and Troubleshooting Bay Dial VPN ServicesC-20 303509-A Rev 00Remote Access Concentrator does not advertise updates.(continued)6. If your

Pagina 74

Troubleshooting303509-A Rev 00 C-21 RAC does not receive updates.1. Are the routes really being advertised?Check whether other routers on the networ

Pagina 75 - Configuring Active RIP

Configuring and Troubleshooting Bay Dial VPN ServicesC-22 303509-A Rev 00Tracing a Packet’s Path at the Remote Access ConcentratorYou can use the pi

Pagina 76

Troubleshooting303509-A Rev 00 C-23 Figure C-1. Network Topology for ping -t ExamplesGiven the topology in Figure C-1, the command:annex# ping –t 13

Pagina 77 - for erpcd Networks

Configuring and Troubleshooting Bay Dial VPN ServicesC-24 303509-A Rev 00Troubleshooting Tunnel ProblemsSince the TMS is an extension of the proprie

Pagina 78 - 5-2 303509-A Rev 00

Troubleshooting303509-A Rev 00 C-25 Operation and Troubleshooting Layer 2 TunnelsUse the log files to troubleshoot your network. The following descr

Pagina 79 - 303509-A Rev 00 5-3

Preface303509-A Rev 00xvii Acronymsseparator ( > ) Shows menu paths. Example: Protocols > IP identifies the IP option on the Protocols menu. ver

Pagina 80 - Tunnel Management Commands

Configuring and Troubleshooting Bay Dial VPN ServicesC-26 303509-A Rev 00Once the tunnel has been established, an entry is placed in the RAC’s Tunne

Pagina 81 - All commands except

Troubleshooting303509-A Rev 00 C-27 The following example shows how you can display the configuration of the LNS using commands that the L2TP script

Pagina 82 - Command Arguments

Configuring and Troubleshooting Bay Dial VPN ServicesC-28 303509-A Rev 00RADIUS session for line 300046 sending access request using identifier 1

Pagina 83

Troubleshooting303509-A Rev 00 C-29 # 23: 03/16/98 15:32:27.597 TRACE SLOT 3 PPP Code: 63IPCP Rejecting Unknown option on circuit 46.The

Pagina 84

Configuring and Troubleshooting Bay Dial VPN ServicesC-30 303509-A Rev 00[2:1]$ show l2tp statL2TP Statistics---------------Slot: 3 SCCRQ

Pagina 85

Troubleshooting303509-A Rev 00 C-31 Listing the IP circuits configured on the box shows the entry that corresponds with the assigned network.[2:1]$

Pagina 86

Configuring and Troubleshooting Bay Dial VPN ServicesC-32 303509-A Rev 00Accounting Log"03/16/1998","15:36:31","LNS_LABNOTE

Pagina 87

303509-A Rev 00 Glossary-1 GlossaryAccess Control Protocol (ACP)Bay Networks software utility that provides a wide range of security features to An

Pagina 88

Configuring and Troubleshooting Bay Dial VPN ServicesGlossary-2 303509-A Rev 00decapsulationStripping protocol-specific information from a data pack

Pagina 89 - 0013ABC0:001234560000

Glossary303509-A Rev 00 Glossary-3 Internet Protocol (IP)Part of the TCP/IP suite of protocols defined in RFC 791. Describes the software responsibl

Pagina 90

Configuring and Troubleshooting Bay Dial VPN Servicesxviii303509-A Rev 00ISO International Organization for StandardizationISP Internet Service Provid

Pagina 91 - Chapter 6

Configuring and Troubleshooting Bay Dial VPN ServicesGlossary-4 303509-A Rev 00NCPNetwork Control Protocol. Software that manages the traffic betwee

Pagina 92 - 6-2 303509-A Rev 00

Glossary303509-A Rev 00 Glossary-5 RIPRouting Information Protocol. A distance-vector protocol in the IP suite (used by IP and IPX network-layer pro

Pagina 93 - DVS0015A

Configuring and Troubleshooting Bay Dial VPN ServicesGlossary-6 303509-A Rev 00Tunnel Management System (TMS)A database of IP tunnel management info

Pagina 94 - Using RADIUS Accounting

303509-A Rev 00Index-1AAccess Control Protocol log file, C-7Access Control Protocol server, 1-10Access Stack Node (ASN), 1-2accountinggateway and tunn

Pagina 95 - RADIUS server

Index-2303509-A Rev 00configuringadjacent host, 8-6adjacent host and static route, 8-2Dial VPN, 1-7Remote Annex software, 4-1static route, 8-7congesti

Pagina 96

303509-A Rev 00Index-3Events Manager, C-8Expedited Remote Procedure Call Daemon. See erpcdFfault event, C-8, C-9forwarding tables, saving, C-13frame r

Pagina 97

Index-4303509-A Rev 00LNSBay Networks implementation, 2-5configuring, 8-13configuring router as, 8-13description, 1-12L2TP security, 2-7operating with

Pagina 98

303509-A Rev 00Index-5primary_authentication_ server_addr, TMS parameter, 5-9primary_dynamic_address_assignment_server_addr, TMS parameter, 5-9problem

Pagina 99 - Messages.”

Index-6303509-A Rev 00sauth, TMS parameter, 5-9scope, 8-18Screen Builder tool, C-11Screen Manager tool, C-10, C-13secondary_accounting_server_addr, TM

Pagina 100

303509-A Rev 00Index-7TMScommands, 5-4database, 5-1description, 3-4managing, 9-1Tunnel Management System, 1-10TMS database, 5-4alternatives, 5-13descr

Pagina 101 - Chapter 7

Preface303509-A Rev 00xix Bay Networks Technical PublicationsYou can now print Bay Networks technical manuals and release notes free, directly from th

Pagina 103 - <slot_number>

ii303509-A Rev 004401 Great America Parkway 8 Federal StreetSanta Clara, CA 95054 Billerica, MA 01821Copyright © 1998 Bay Networks, Inc.All rights res

Pagina 105 - Gateway Accounting Messages

303509-A Rev 00 1-1 Chapter 1Tunneling OverviewBay Networks Dial Virtual Private Network Services provides secure dial-access services for corporate

Pagina 106

Configuring and Troubleshooting Bay Dial VPN Services1-2 303509-A Rev 00Dial VPN encapsulates multiprotocol data within an IP datagram. It then send

Pagina 107 - Chapter 8

Tunneling Overview303509-A Rev 00 1-3 Dial VPN dynamically creates a tunnel when it connects to the remote node’s home network. One end point of the

Pagina 108 - DVS0008A

Configuring and Troubleshooting Bay Dial VPN Services1-4 303509-A Rev 00Layer 3 TunnelingIn Layer 3 tunneling, the tunnel exists between the Network

Pagina 109 - 303509-A Rev 00 8-3

Tunneling Overview303509-A Rev 00 1-5 How a Dial VPN Network FunctionsAny authorized remote user (using a PC or dial-up router) who has access to a

Pagina 110 - (continued)

Configuring and Troubleshooting Bay Dial VPN Services1-6 303509-A Rev 00Figure 1-2. Dial VPN Network with Connections to Different Destination Types

Pagina 111

Tunneling Overview303509-A Rev 00 1-7 For Bay Networks routers used with a Layer 3 Dial VPN tunnel, you must specify an adjacent host and a static r

Pagina 112

Configuring and Troubleshooting Bay Dial VPN Services1-8 303509-A Rev 00The following considerations apply only to Layer 2 (L2TP) tunnels:• If the P

Pagina 113 - 303509-A Rev 00 8-7

Tunneling Overview303509-A Rev 00 1-9 GatewayUsed only in Layer 3 networks, the gateway can be an ASN, BLN, BLN-2, BCN, or System 5000 MSX equipped

Pagina 114 - 8-8 303509-A Rev 00

303509-A Rev 00iiiBay Networks, Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using the accom

Pagina 115 - 303509-A Rev 00 8-9

Configuring and Troubleshooting Bay Dial VPN Services1-10 303509-A Rev 00Tunnel Management Server (TMS)The mechanism for identifying tunneled users

Pagina 116

Tunneling Overview303509-A Rev 00 1-11 L2TP Access Concentrator (LAC)The L2TP access concentrator (LAC) resides at the ISP network. The LAC establis

Pagina 117

Configuring and Troubleshooting Bay Dial VPN Services1-12 303509-A Rev 00Enterprise subscribers of this service must configure the CPE router to all

Pagina 118

Tunneling Overview303509-A Rev 00 1-13 • Providing accounting services for corporate billingFor Layer 3 tunnels, the RADIUS client of this server re

Pagina 119 - Enabling L2TP

Configuring and Troubleshooting Bay Dial VPN Services1-14 303509-A Rev 00DHCP ServerIf you implement the optional Dynamic Host Configuration Protoco

Pagina 120

303509-A Rev 00 2-1 Chapter 2Dial VPN Layer 2 TunnelingThis chapter describes how a Layer2 Dial VPN tunnel functions. Among these concepts are how a

Pagina 121

Configuring and Troubleshooting Bay Dial VPN Services2-2 303509-A Rev 00Figure 2-1. Layer 2 Tunnel Packet PathBuilding a Network for Layer 2 Tunneli

Pagina 122

Dial VPN Layer 2 Tunneling303509-A Rev 00 2-3 2.Install and configure any intermediate nodes on the WAN.The WAN can include intermediate nodes. For

Pagina 123 - (continued)

Configuring and Troubleshooting Bay Dial VPN Services2-4 303509-A Rev 00• The CPE router that is the end point of Layer 2 tunnels is configured as t

Pagina 124 - Framed-IPX-Network

Dial VPN Layer 2 Tunneling303509-A Rev 00 2-5 Figure 2-2. L2TP Packet Encapsulation ProcessBay Networks L2TP ImplementationIn an L2TP tunnel, the Ba

Pagina 125 - 303509-A Rev 00 8-19

iv303509-A Rev 00its own data and information and for maintaining adequate procedures apart from the Software to reconstruct lost or altered files, d

Pagina 126

Configuring and Troubleshooting Bay Dial VPN Services2-6 303509-A Rev 00• The LNS performs user authentication with a RADIUS server to prevent unaut

Pagina 127 - Creating a Superscope

Dial VPN Layer 2 Tunneling303509-A Rev 00 2-7 When the LAC receives a call, it forwards the domain name to the TMS. The domain name is the portion o

Pagina 128

Configuring and Troubleshooting Bay Dial VPN Services2-8 303509-A Rev 00During tunnel authentication, the LNS identifies the L2TP client or LAC by c

Pagina 129 - Managing a Dial VPN Network

Dial VPN Layer 2 Tunneling303509-A Rev 00 2-9 Figure 2-3. Tunnel Authentication Control MessagesAfter tunnel authentication is complete, it need not

Pagina 130 - 9-2 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN Services2-10 303509-A Rev 00RADIUS AccountingThe RADIUS server can provide accounting services in addit

Pagina 131 - Planning Worksheet

Dial VPN Layer 2 Tunneling303509-A Rev 00 2-11 Remote Router ConfigurationIf the host at the remote site is a Bay Networks router, you may need to c

Pagina 132 - A-2 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN Services2-12 303509-A Rev 00Examples of L2TP TunnelsFigure 2-4 shows an L2TP network that uses a LAC to

Pagina 133 - For Each Destination Site

Dial VPN Layer 2 Tunneling303509-A Rev 00 2-13 Making a Connection Across an L2TP NetworkThe following steps explain how a remote user connects acro

Pagina 134 - For Each Remote Node

Configuring and Troubleshooting Bay Dial VPN Services2-14 303509-A Rev 00When Does Dial VPN Tear Down the Tunnel?The LAC brings down the tunnel for

Pagina 135 - Syslog Messages

303509-A Rev 00 3-1 Chapter 3Dial VPN Layer 3 TunnelingThis chapter describes how a Layer 3 Dial VPN tunnel functions. Among these concepts are how

Pagina 136

303509-A Rev 00 vContentsPrefaceBefore You Begin ...

Pagina 137

Configuring and Troubleshooting Bay Dial VPN Services3-2 303509-A Rev 00Figure 3-1. Layer 3 Tunnel Packet PathBuilding a Network for Layer 3 Tunneli

Pagina 138 - TMS Syslog Messages

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-3 3.Install the software for the tunnel management server, Remote Access Concentrator, and (for the erpc

Pagina 139

Configuring and Troubleshooting Bay Dial VPN Services3-4 303509-A Rev 0010.Make sure that the home network is configured to connect to the Dial VPN

Pagina 140

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-5 The Grant message contains the following information, which is stored in the TMS database:• Remote nod

Pagina 141

Configuring and Troubleshooting Bay Dial VPN Services3-6 303509-A Rev 00How the TMS Database WorksThe TMS database (by default, UNIX ndbm) resides o

Pagina 142

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-7 Using DHCP for Dynamic IP Address AllocationThis method requires a DHCP server on the home/corporate n

Pagina 143

Configuring and Troubleshooting Bay Dial VPN Services3-8 303509-A Rev 00DHCP discover request to the DHCP server on the home network, and the server

Pagina 144

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-9 Using RADIUS for Dynamic IP Address AllocationEach dial-in user retains exclusive uses of a unique IP

Pagina 145 - Troubleshooting

Configuring and Troubleshooting Bay Dial VPN Services3-10 303509-A Rev 00The BSAC (RADIUS) administrator at the customer’s site must enter one or mo

Pagina 146 - Preventing Problems

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-11 Figure 3-3. Dial VPN Dynamic IP Address Management SequenceAt the start of service delivery, a client

Pagina 147 - Preparing to Troubleshoot

vi 303509-A Rev 00RADIUS Accounting Server ...1-13DHCP Server ...

Pagina 148 - Troubleshooting Worksheet

Configuring and Troubleshooting Bay Dial VPN Services3-12 303509-A Rev 00server, which sends back an acknowledgment that it has received the packet.

Pagina 149 - 303509-A Rev 00 C-5

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-13 If the TMS finds a match in its database for both the user and domain names, it determines that this

Pagina 150 - Cable Guide

Configuring and Troubleshooting Bay Dial VPN Services3-14 303509-A Rev 00If the home network is configured to assign IP addresses dynamically using

Pagina 151

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-15 Figure 3-4. Packet Encapsulation and Decapsulation ProcessFlag FlagAddress Control Protocol Data FCS

Pagina 152 - C-8 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN Services3-16 303509-A Rev 00How a Packet Moves Through a Dial VPN NetworkA data packet moves from a rem

Pagina 153

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-17 5.The CPE router decapsulates the frame relay or PPP packet and routes the data to the intended recip

Pagina 154

Configuring and Troubleshooting Bay Dial VPN Services3-18 303509-A Rev 00The data packet travels from the home network to the remote node using a si

Pagina 155 - 303509-A Rev 00 C-11

Dial VPN Layer 3 Tunneling303509-A Rev 00 3-19 When Does Dial VPN Tear Down the Tunnel?Dial VPN tears down the tunnel when any of the following situ

Pagina 157 - 303509-A Rev 00 C-13

303509-A Rev 00 4-1 Chapter 4Configuring the Remote Access ConcentratorThis chapter describes how to use the command line interface (CLI) commands t

Pagina 158 - C-14 303509-A Rev 00

303509-A Rev 00 viiA Day in the Life of a Layer 3 Packet ...3-14How a Packet

Pagina 159

Configuring and Troubleshooting Bay Dial VPN Services4-2 303509-A Rev 001.Install the RAC software.Use the installation script supplied for the RAC,

Pagina 160

Configuring the Remote Access Concentrator303509-A Rev 00 4-3 set port ppp_ncp all (<---This could be set to ipcp and ipxcp.)The slip_ppp_securit

Pagina 161

Configuring and Troubleshooting Bay Dial VPN Services4-4 303509-A Rev 004.Enable the appropriate options.To display the options that are enabled, us

Pagina 162

Configuring the Remote Access Concentrator303509-A Rev 00 4-5 begin_session v120bearer datacalled_no <called_number>call_action v.120set mode

Pagina 163 - Using Command Line Interfaces

Configuring and Troubleshooting Bay Dial VPN Services4-6 303509-A Rev 00For a default route, the syntax is: route add<default> <next_hop>

Pagina 164

Configuring the Remote Access Concentrator303509-A Rev 00 4-7 During the initial boot of the operational code, the ROM monitor requires the address

Pagina 165 - Command Line Interfaces

Configuring and Troubleshooting Bay Dial VPN Services4-8 303509-A Rev 00Configuring the RAC to Advertise RIP 1 and/or RIP 2 UpdatesBy default, activ

Pagina 166 - C-22 303509-A Rev 00

303509-A Rev 00 5-1 Chapter 5Configuring TMS and Security for erpcd NetworksIn a Dial VPN network, tunnel users are authenticated by a RADIUS server

Pagina 167 - DVS0005A

Configuring and Troubleshooting Bay Dial VPN Services5-2 303509-A Rev 00Managing TMS Using the TMS Default DatabaseTunnel management in an erpcd-bas

Pagina 168 - C-24 303509-A Rev 00

Configuring TMS and Security for erpcd Networks303509-A Rev 00 5-3 The syntax of the command that creates a TMS entry is:tms_dbm add <domain>

Pagina 169 - Troubleshooting the LAC

viii 303509-A Rev 00Chapter 8 Requirements Outside the ISP NetworkConfiguring a Static Route and an Adjacent Host ...

Pagina 170 - Troubleshooting the LNS

Configuring and Troubleshooting Bay Dial VPN Services5-4 303509-A Rev 00Table 5-1 lists the tunnel management (tms_dbm) commands, and Table 5-2 list

Pagina 171

Configuring TMS and Security for erpcd Networks303509-A Rev 00 5-5 All commands except add and help return an error if the entry is not found.rekeyC

Pagina 172

Configuring and Troubleshooting Bay Dial VPN Services5-6 303509-A Rev 00Command ArgumentsThe tunnel management commands use common arguments to spec

Pagina 173

Configuring TMS and Security for erpcd Networks303509-A Rev 00 5-7 ha=<ha_addr>Not used in Dial VPN. Supported only for compatibility with pre

Pagina 174

Configuring and Troubleshooting Bay Dial VPN Services5-8 303509-A Rev 00hwtype=<hw_type>hwaddr=<hw_addr>hwalen=<hw_addr_len>hwtype

Pagina 175

Configuring TMS and Security for erpcd Networks303509-A Rev 00 5-9 tutype=<tunnel_type>Specifies the type of tunnel to establish. For a Layer

Pagina 176 - C-32 303509-A Rev 00

Configuring and Troubleshooting Bay Dial VPN Services5-10 303509-A Rev 00acctp=<accounting_protocol>Specifies the accounting protocol used bet

Pagina 177 - Glossary

Configuring TMS and Security for erpcd Networks303509-A Rev 00 5-11 passwd=<password>Relevant only for Layer 2 tunnels, this parameter specifi

Pagina 178

Configuring and Troubleshooting Bay Dial VPN Services5-12 303509-A Rev 00Configuring Local Authentication Using the ACPDial VPN relies on the remote

Pagina 179

Configuring TMS and Security for erpcd Networks303509-A Rev 00 5-13 For IPX, use the network and node address combination; for example:0013ABC0:0012

Pagina 180

303509-A Rev 00 ixAppendix A Planning WorksheetBayDVS Network Planning Worksheet ...

Pagina 182 - Network (VPN)

303509-A Rev 00 6-1 Chapter 6Configuring the TMS Using Local RADIUSYou can configure the TMS database to use a RADIUS server on the service provider

Pagina 183

Configuring and Troubleshooting Bay Dial VPN Services6-2 303509-A Rev 00The NAS uses RADIUS accounting messages to determine when the TMS tunnel to

Pagina 184

Configuring the TMS Using Local RADIUS303509-A Rev 00 6-3 Figure 6-1. Message Exchanges Supporting RADIUS TMS OperationsLCP negotiateCHAP initiation

Pagina 185

Configuring and Troubleshooting Bay Dial VPN Services6-4 303509-A Rev 00Using RADIUS AccountingThe NAS logs the tunnel-bound link sessions to the se

Pagina 186

Configuring the TMS Using Local RADIUS303509-A Rev 00 6-5 Table 6-2 summarizes the user stop messages that the NAS sends to the provider’s RADIUS se

Pagina 187

Configuring and Troubleshooting Bay Dial VPN Services6-6 303509-A Rev 00RADIUS Attributes That Support TunnelingThe RADIUS attributes that support T

Pagina 188

Configuring the TMS Using Local RADIUS303509-A Rev 00 6-7 Table 6-4 lists the RADIUS attributes that the Layer 3 gateway supports.Table 6-4. RADIUS

Pagina 189

Configuring and Troubleshooting Bay Dial VPN Services6-8 303509-A Rev 00TMS Parameters for erpcd-Based and All-RADIUS Tunnels While TMS operation is

Pagina 190

Configuring the TMS Using Local RADIUS303509-A Rev 00 6-9 TMS System Log (Syslog) MessagesTMS writes its system and error messages to the system log

Comentarios a estos manuales

Sin comentarios