112
checks the user validity according to the received information and t he locally configured
authentication method.
When mandatory CHAP authentication is configured, a user who depends on an LAC to initiate
tunneling requests is authenticated by both the LAC and the LNS for increased security. Some users
might not support the authentication on the LNS. In this situation, do not configure this command,
because CHAP authentication on the LNS will fail.
This command is available only on L2TP groups in LNS mode.
This command takes effect only on NAS-initiated L2TP tunnels.
The
mandatory-lcp
command takes precedence over this command. If both commands are
configured for an L2TP group, the LNS performs LCP renegotiation with the user.
Examples
# Force the LNS to perform CHAP authentication for users.
<Sysname> system-view
[Sysname] l2tp-group 1 mode lns
[Sysname-l2tp1] mandatory-chap
Related commands
mandatory-lcp
mandatory-lcp
Use
mandatory-lcp
to force an LNS to perform LCP negotiation with users.
Use
undo mandatory-lcp
to restore the default.
Syntax
mandatory-lcp
undo mandatory-lcp
Default
An LNS does not perform LCP negotiation with users.
Views
L2TP group view
Predefined user roles
network-admin
Usage guidelines
By default, to establish a NAS-initiated tunnel, the user performs LCP negotiation with the LAC. If the
negotiation succeeds, the LAC initiates a t unneling request and sends the negotiation results
(including authentication information) to the LNS. Then, the LNS determines whether the user is
valid based on the information received instead of performing LCP renegotiation with the user.
If you do not expect the LNS to accept LCP negotiation parameters, configure this command to
perform an LCP negotiation between the LNS and the user. In this case, the information sent by the
LAC will be ignored.
Some users might not support LCP negotiation. In this case, do not configure this command because
LCP negotiation will fail.
This command is available only on L2TP groups in LNS mode.
This command takes effect only on NAS-initiated L2TP tunnels.
Summary of Contents for MSR810
Page 148: ...136 Related commands timer hold...
Page 331: ...319 Related commands timer hold...