345
Enabling NAT traversal for the CPE
For the connection request initiated from the ACS to reach the CPE, you must enable NAT traversal
feature on the CPE when a NAT gateway resides between the CPE and the ACS.
The NAT traversal feature complies with RFC 3489 Simple Traversal of UDP Through NATs (STUN).
The feature enables the CPE to discover the NAT gateway, and obtain an open NAT binding (a public
IP address and port binding) through which the ACS can send unsolicited packets. The CPE sends
the binding to the ACS when it initiates a connection to the ACS. For the connection requests sent by
the ACS at any time to reach the CPE, the CPE maintains the open NAT binding.
NOTE:
Connection requests initiated from the CPE can reach the ACS through a NAT gateway without NAT
traversal.
To enable NAT traversal on the CPE:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter CWMP view.
cwmp
N/A
3.
Enable NAT traversal.
cwmp cpe stun enable
By default, NAT traversal is
disabled on the CPE.
Specifying an SSL client policy for HTTPS connection to ACS
CWMP uses HTTP or HTTPS for data transmission. If the ACS uses HTTPS for secure access, its
URL begins with
https://
. You must configure an SSL client policy for the CPE to authenticate the
ACS for HTTPS connection establishment. For more information about configuring SSL client
policies, see
Security Configuration Guide
.
To specify an SSL client policy for the CPE to establish an HTTPS connection to the ACS:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter CWMP view.
cwmp
N/A
3.
Specify an SSL client policy.
ssl client-policy
policy-name
By default, no SSL client policy is
specified.
Displaying and maintaining CWMP
Execute
display
commands in any view.
Task
Command
Display CWMP configuration.
display cwmp configuration
Display the current status of CWMP.
display cwmp status
Summary of Contents for FlexNetwork 10500 SERIES
Page 224: ...213 ...
Page 311: ...300 Now the system can record log information to the specified file ...