
Supported RADIUS Attribute/
Value Pairs for L2TP operation
153
h Sets the connection not to send HDLC framing headers on all PPP packets. This is in accordance
with the L2TP/PPP RFCs. This does not work on BT 21CN BRASs.
F Sets TCP MTU fix flag which causes the MTU option in TCP SYN to be adjusted if necessary to
fit MTU.
f Sets no TCP MTU fix
M Sets the connection to ignore the MRU. Actually, the MRU is used to generate ICMP errors for
IPv6 and IPv4 with DF set, but otherwise full size packets are sent on the connection even if a lower
MRU was advised. This is in accordance with the PPP RFC but breaks some routers that do not
accept 1500 byte packets (e.g. PPPoE)
m Sets the connection to fragment IPv4 packets with DF not set that are too big for the advised MRU.
This is teh default
L This is not a filter and not confirmed back on accounting start and not valid on Change of
Authorisation. It forces a restart of LCP negotiation. This is useful when BRASs lie about negotiated
LCP (such as BTs 21CN BRASs)
l This is not a filter and not confirmed back on accounting start and not valid on Change of
Authorisation. It stops an LCP negotiation restart that may be planned, e.g. due to an MRU mismatch.
X Pad packets to 74 bytes if length fields appears to be less - needed to work around bug in BT 20CN
BRAS for IPv6 in IP over LCP mode
C Send all IPv4 and IPv6 using the LCP type code (only works if FireBrick doing PPP at far end)
O Mark session as low-priority (see shaper and damping)
P Mark session as premium (see shaper and damping)
D Mark session as blackhole (Normal IPv4/IPv6 routes are announced as black hole routes, and any
BGP is not restricted to local-as, etc. Does not apply to 6over4 routes)
d Mark session as not blackhole
b Disable anti-spoofing source filtering
Sn Set LCP echo rate to n seconds (default 1)
sn Set LCP timeout rate to n seconds (default 10)
q[+]n Specify [or add to] quota for tx bytes. Use either q or Q. Action depends on Terminate-Action.
Q[+]n Specify [or add to] quota for total (tx+rx) bytes.
For change of authorisation the absence of a filter has no effect. To set normal routing table 0 zero, send T0.
To set not a member of a CUG send A0.
F.9. Notes
F.9.1. L2TP relay
L2TP relay means that an incoming call (ICRQ) is relayed to another L2TP endpoint. The decision of which
calls to relay to what endpoint can be made in one of two ways:-
• Configured pattern match based on calling number, called number, or login.
• RADIUS response to initial authentication request advising new endpoint for connection.
A test is made against the config on the initial connection based on known data. This is calling number (if
present), called number (if present) and login (proxy_auth_name if present). If a match is found the call is
relayed with no additional PPP packets exchanged.
If there is no proxy LCP provided, or the provided negotiation conflicts with the configuration, then LCP
negotiation is completed.
Содержание FireBrick FB2700
Страница 1: ...FireBrick FB2700 User Manual FB2700 Versatile Network Appliance ...
Страница 2: ......