ESR-Series. User manual
468
•
•
To clear L2TP server session counters, use the following command:
esr# clear remote-access counters l2tp server remote-workers
To end L2TP server session for user 'fedor', use one of the following commands:
esr# clear remote-access session l2tp username fedor
esr# clear remote-access session l2tp server remote-workers username fedor
To view L2TP server configuration, use the following command:
esr# show remote-access configuration l2tp remote-workers
15.3 Configuring server for remote access to corporate network via OpenVPN protocol
OpenVPN is a sophisticated tool based on SSL that implements Virtual Private Networks (VPN), enables
remote access and solves many different tasks related to data transmission security.
15.3.1 Configuration algorithm
Step
Description
Command
Keys
1
Create OpenVPN server profile.
esr(config)# remote-access
openvpn <NAME>
<NAME> – OpenVPN server
profile name, set by the string
of up to 31 characters.
2
Specify the description of the
configured server (optionally).
esr(config-openvpn-server)#
description <DESCRIPTION>
<DESCRIPTION> – OpenVPN
server description, set by the
string of up to 255 characters.
3
Define the subnet from which IP
addresses are leased to users. (only for
tunnel ip).
esr(config-openvpn-server)#
network <ADDR/LEN>
<ADDR/LEN> – subnet address,
set in the following format:
AAA.BBB.CCC.DDD/EE –
network IP address with prefix
mask, where AAA-DDD take
values of [0..255] and EE takes
values of [1..32].
4
Specify an encapsulated protocol.
esr(config-openvpn-server)#
protocol <PROTOCOL>
<PROTOCOL> – encapsulation
type, possible values:
TCP encapsulation in
TCP segments;
UDP encapsulation in
UDP datagrams.
In addition to L2TP server creation, you should open UDP port 500, 1701, 4500 designed for
connection handling and enable ESP (50) and GRE protocol (47) for the tunnel traffic in the firewall.
Содержание ESR Series
Страница 218: ...ESR Series User manual 218 ...
Страница 234: ...ESR Series User manual 234 In addition to RIP protocol configuration open UDP port 520 in the firewall ...
Страница 306: ...ESR Series User manual 306 Parameter targeted LDP Hold timer 45 seconds Keepalive holdtime 180 seconds ...
Страница 452: ...ESR Series User manual 452 Step Description Command Keys 4 Enable Tracking object esr config tracking enable ...
Страница 514: ...ESR Series User manual 514 esr show ntp peers ...