For a given domain map, you can choose one of two
methods to map the domain to an L2TP tunnel locally on the router:
Configure tunnels for a domain map and then define tunnel
attributes from Domain Map Tunnel configuration mode.
Configure a tunnel group and then define the attributes
for its tunnels from Tunnel Group Tunnel Configuration mode. Use this
method only when no tunnels are currently defined for the domain map
from Domain Map Tunnel configuration mode. By default, tunnel groups
are not assigned to the domain map.
After configuring a tunnel group and the attributes
for its tunnels, you can assign the tunnel group to the domain map
from Domain Map mode. The tunnel group reference in the domain map
is used instead of tunnel definitions configured from Domain Map Tunnel
The RADIUS server can reference tunnel groups through
the RADIUS Tunnel Group [26-64] attribute. The advantages of RADIUS
support for tunnel groups are:
The RADIUS server can maintain a single tunnel group attribute
associated with each user instead of sets of tunnel attributes for
The RADIUS server can authenticate users before attempting
to establish tunnels.