7-4
Stinger®
IP2000 Configuration Guide
Broadband RAS Configuration
Required setup for PPPoA and PPPoE connections
Most sites change the default setting of the
receive-auth-mode
parameter to ensure
authentication of a PPP request before a session can be established. For example:
admin> read answer-defaults
admin> set ppp-options receive-auth-mode = any-ppp-auth
admin> write -f
With this setting, the system accepts session requests that provide any of the
supported PPP authentication methods, but it drops requests that do not offer any
authentication protocols during session negotiation.
The following commands enable bidirectional authentication for sessions that use
CHAP and specify the proper settings in the
connection
or RADIUS profile:
admin> set ppp-answer bidirectional-auth = allowed
admin> write -f
With these settings, if a calling device accepts CHAP authentication, the system
attempts to negotiate bidirectional CHAP, but does not reject the request if the
negotiation fails. However, if bidirectional CHAP is negotiated, authentication must
succeed in both directions. For related information, see “Sample PPPoA connection
with bidirectional CHAP authentication” on page 7-7.
Terminating traffic on a LIM internal interface
For all installed LIMs that can terminate PPPoA or PPPoE calls, the system creates an
atm-internal
profile for the LIM’s internal ATM segmentation assembly and
enabled
The
enabled
parameter must be set to
yes
(the default)
for the system to answer PPP session requests.
receive-auth-mode
With the default
no-ppp-auth
setting, the Stinger unit
does not request authentication. If set to a non-default
value, the Stinger unit requests an authentication
protocol, and the client must accept one of the options
the system offers.
bi-directional-auth
Support for bidirectional CHAP. If set to
allowed
or
required
, the system negotiates bidirectional CHAP if
the client’s
connection
profile specifies the proper
settings.
substitute-send-name
System name to send to clients for bidirectional CHAP
authentication, if different from the
name
setting in the
system
profile.
idle-timer
With a
call-type
setting of
off
in a client profile, the
system uses the
idle-timer
value to terminate the
session after a default interval of 2 minutes. You can
configure a different default interval here or in the
client’s
session-options
subprofile, by specifying the
maximum number of consecutive seconds a session can
remain idle before it is terminated.
max-call-duration
Maximum number of minutes of connect time for a PPP
session. The default zero value disables the timer.
Parameter
Setting
Содержание Stinger IP2000
Страница 1: ...Stinger IP2000 Configuration Guide Part Number 7820 0976 004 For software version 9 6 0 January 2004 ...
Страница 4: ......
Страница 12: ......
Страница 14: ......
Страница 34: ......
Страница 86: ......
Страница 100: ......
Страница 120: ......
Страница 150: ......
Страница 162: ......
Страница 208: ......