
Supported RADIUS Attribute/
Value Pairs for L2TP operation
84
Tunnel-Medium-Type
65 If specified must be 1 (IPv4) or 2 (IPv6), syntax of endpoint is used if this is
not specified
Tunnel-Server-
Endpoint
67 Text IPv4 or IPv6 address of endpoint (FQDN is not accepted)
Tunnel-Client-Auth-
ID
90 Hostname to quote on outgoing tunnel, if omitted then configured FireBrick
hostname is used
Tunnel-Password
69 Shared secret to use on outgoing tunnel (encrypted), if omitted then assumed
no secret
Tunnel-Assignment-
ID
81 Name of outgoing tunnel shaper/graph. Also groups sessions together in a
tunnel as per RFC. Only use valid text graph names.
Tunnel-Preference
83 Specifies preference order when multiple tagged endpoints sent
Note that whilst a RADIUS response is normally relatively small in can get larger when multiple tunnel
endpoints are included. Fragmented responses are handled but there is an internal limit to the size of response
that can be processed - as such we recommend keeping the response to a single un-fragmented packet of up to
1500 bytes. You can use tag 0 for common settings such as Tunnel-Client-Auth-ID or Tunnel-Password when
using multiple endpoints in order to reduce the size of the response.
F.2.1.1. Prefix Delegation
The RADIUS authentication response can include Delegated-IPv6-Prefix, Framed-IPv6-Prefix, and Framed-
IPv6-Route in order to route native IPv6 prefixes to the line. If there are any native IPv6 routes, or the Framed-
IPv6-Interface attribute was specified, then IPV6CP negotiation is started. Framed-IPv6-Route can also be used
to added IPv4 tunneled routes to the line. The FE80::/10 link local address negotiated with IPV6CP is not added
to the routing for the line.
The client can send a Router solicitation to which the FireBrick will reply advising to use DHCPv6 for
addressing. Once a router solicitation is sent, periodic Router Advertisements will then be sent on the connection
by the Firebrick.
The client can use DHCPv6 to request an IA_NA (/128 link address), IA_TA (/128 temp link address), IA_PD
(Prefic delegation) and DNS servers. Prefixes are delegated based on the order in the DHCPv6 request and the
order of Delegated-IPv6-Prefix, Framed-IPv6-Prefix, and then Framed-IPv6-Route, with multiple such entries
in the order that they appeared in the RADIUS response. Such prefixes are not split up if a smaller prefix is
requested, but the first part of a prefix is delegated.
F.2.2. Rejected authentication
Table F.3. Access-Reject
AVP
No. Usage
Reply-Message
18 Reply message sent on PPP authentication response
Note that an authentication reject will normally cause the reply message to be sent as an authentication reject
message. The reply "Try another" causes the L2TP session to be closed with result/error 2/7 (Try another)
without sending an authentication reply on PPP.
F.3. Accounting Start
Table F.4. Accounting-Start
AVP
No. Usage
Acct-Status-Type
40 1 Start
Содержание FB6602
Страница 1: ...FireBrick FB6602 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......
Страница 60: ...Profiles 45 profile name Off set false profile name On set true...