
Supported RADIUS Attribute/
Value Pairs for L2TP operation
88
• To clear the session timeout send a value of 0.
• To clear outbound shaping send connect speed of "0".
No other parameters are supported, and if sent then they are ignored
F.8. Filter ID
The Filter-ID can be set in authentication response and change of authorisation. There can be many records.
Each can have many filters. Each filter is of the form of a letter possibly followed by number digits. The
accounting start lists relevant filters that have been set, each in a separate filter-id AVP. Unknown filters are
ignored.
Table F.9. Filter-ID
Filter meaning
Tn Set routing table for payload traffic. This can be used for private routing, and for walled garden /
credit control
An Specify this connection is a member of a closed user group n (1-32767) but has normal IP access
as well. This connection is not filtered by traffic can go to/from connections that are filtered in the
same CUG
Rn Specify this connection is a member of a closed user group n (1-32767) and is restricted to sending
traffic to/from connections in the same CUG.
H Sets the connection to send HDLC framing headers on all PPP packets. This adds 2 extra byte to
the packet. This is the default setting.
h Sets the connection not to send HDLC framing headers on all PPP packets. This is in accordance
with the L2TP/PPP RFCs. This does not work on BT 21CN BRASs.
F Sets TCP MTU fix flag which causes the MTU option in TCP SYN to be adjusted if necessary to
fit MTU.
f Sets no TCP MTU fix
M Sets the connection to ignore the MRU. Actually, the MRU is used to generate ICMP errors for
IPv6 and IPv4 with DF set, but otherwise full size packets are sent on the connection even if a lower
MRU was advised. This is in accordance with the PPP RFC but breaks some routers that do not
accept 1500 byte packets (e.g. PPPoE)
m Sets the connection to fragment IPv4 packets with DF not set that are too big for the advised MRU.
This is teh default
L This is not a filter and not confirmed back on accounting start and not valid on Change of
Authorisation. It forces a restart of LCP negotiation. This is useful when BRASs lie about negotiated
LCP (such as BTs 21CN BRASs)
l This is not a filter and not confirmed back on accounting start and not valid on Change of
Authorisation. It stops an LCP negotiation restart that may be planned, e.g. due to an MRU mismatch.
X Pad packets to 74 bytes if length fields appears to be less - needed to work around bug in BT 20CN
BRAS for IPv6 in IP over LCP mode
C Send all IPv4 and IPv6 using the LCP type code (only works if FireBrick doing PPP at far end)
O Mark session as low-priority (see shaper and damping)
P Mark session as premium (see shaper and damping)
Sn Set LCP echo rate to n seconds (default 1)
sn Set LCP timeout rate to n seconds (default 10)
bn Disable anti-spoofing source filtering
Содержание FB6602
Страница 1: ...FireBrick FB6602 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......
Страница 60: ...Profiles 45 profile name Off set false profile name On set true...