
Configuring and Troubleshooting Bay Dial VPN Services
2-14 302272-A Rev. 00
When Does Dial VPN Tear Down the Tunnel?
The LAC brings down the tunnel for any one of the following reasons:
• A network failure occurs.
• The LAC or other equipment at the ISP is not operating properly. If the LAC
fails, all tunnel users are disconnected.
• There are no active sessions inside the tunnel.
An individual session ends when a remote user disconnects the call, but
multiple sessions can run inside a single tunnel.
• The system administrator at the ISP terminates the user connection.
• The LAC is not responding to a Hello packet from the LNS.
For the LAC to reestablish a tunnel, the remote user must place a new call.
If the LAC fails, all tunnel users are disconnected and the active user counts are
decremented. However, there is no quick way to determine when a LAC fails. The
logging connection may not be reset until after new tunnel users have connected.
When a LAC starts, one of the first things it does is open its ACP-logging
connection. When a new logging connection opens, TMS decrements the
appropriate counts for each domain that had a user connected to the LAC. If this is
the first time the LAC has come up, then there will be nothing to decrement.
If the TMS fails, a LAC can detect the failure through the failure of the logging
connection. The LAC falls back to secondary servers, if any. Unless the database
is shared by the TMS servers, the count of current users is lost.
If the TMS database runs out of disk space while tms_dbm is running, the user
sees an error message. The error message may not state what caused the error. If
there is a shortage of disk space and erpcd cannot create a lock file or add a LAC
to the TMS database, TMS generates a syslog message and the user cannot make a
connection to the LAC.
Note:
If you enter the
reset security
command, a new user who tries to make
a connection with the LAC causes the maximum number of users count to
decrement, even though users with existing connections are still connected.
This means that the maximum number of users count may be exceeded. As
users with existing connections disconnect, the count will synchronize and
correspond to the actual number of users connected.
Comentarios a estos manuales