Configuring Access Profiles for L2TP or PPP Parameters (NSM
Procedure)
You can set up access profiles to validate Layer 2 Tunneling
Protocol (L2TP) connections and session requests. You can configure
multiple profiles. You can also configure multiple clients for each
profile. See the following topics:
- Configuring Access Profile (NSM Procedure)
- Configuring Accounting Parameters for Access Profiles (NSM
Procedure)
- Configuring the Accounting Order (NSM Procedure)
- Configuring the Authentication Order (NSM Procedure)
- Configuring the Authorization Order (NSM Procedure)
- Configuring the L2TP Client (NSM Procedure)
- Configuring the Client Filter Name (NSM Procedure)
- Configuring the LDAP Options (NSM Procedure)
- Configuring the LDAP Server (NSM Procedure)
- Configuring the Provisioning Order (NSM Procedure)
- Configuring RADIUS Parameters for AAA Subscriber Management
(NSM Procedure)
- Configuring the RADIUS Parameters (NSM Procedure)
- Configuring the RADIUS for Subscriber Access Management, L2TP,
or PPP (NSM Procedure)
- Configuring Session Limit (NSM Procedure)
Configuring Access Profile (NSM Procedure)
To configure an access profile in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 1.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 1: Access
Profile Properties Configuration Details
| Task |
Your Action |
Configure access profile properties.
|
- Click Add new entry next to Profile.
- In the Name box, enter the name of
the profile.
- In the Comment box, enter the comment.
|
Configuring Accounting Parameters for Access Profiles (NSM
Procedure)
To configure RADIUS accounting parameters for an access
profile in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 2.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 2: Accounting
Parameter Configuration Details
| Task |
Your Action |
Configure RADIUS accounting parameters and
enable RADIUS accounting for an access profile.
|
- Click Add new entry next to Profile.
- Click Accounting next to profile.
- In the Comment box, enter the comment.
- Select the Accounting Stop On Failure check box to configure RADIUS accounting to send an Acct-Stop message
when client access fails AAA but the AAA server grants access.
- Select the Accounting Stop On Access Deny check box to configure RADIUS accounting to send an Acct-Stop message
when the AAA server denies a client access.
- Select the Immediate Update check
box to configure the router to send an Acct-Update message to the
RADIUS accounting server on receipt of a response (for example, an
ACK or timeout) to the Acct-Start message.
- From the Update Interval list, select
the amount of time between updates, in minutes.
Range: 10 through 1440 minutes
Default: no updates
- From the Statistics list, select
the time statistics for the sessions being managed by AAA.
|
Configuring the Accounting Order (NSM Procedure)
Beginning with JUNOS Release 8.0, you can configure RADIUS
accounting for an Layer 2 Tunneling Protocol (L2TP) profile. With
RADIUS accounting enabled, Juniper Networks routers, acting as RADIUS
clients, can notify the RADIUS server about user activities such as
software logins, configuration changes, and interactive commands.
When you enable RADIUS accounting for an L2TP profile, it applies
to all the clients within that profile. You must enable RADIUS accounting
on at least one LT2P profile for the RADIUS authentication server
to send accounting stop and start messages.
To configure accounting order in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 3.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 3: Accounting Order
Configuration Details
| Task |
Your Action |
Configure the accounting order.
|
- Click Add new entry next to Profile.
- Click Accounting Order next to Profile.
- Click Add new entry next to Accounting
Order.
- In the New accounting-order window,
select radius to use RADIUS accounting method.
|
Configuring the Authentication Order (NSM Procedure)
You can configure the order in which the JUNOS Software
tries different authentication methods when authenticating peers.
For each access attempt, the software tries the authentication methods
in order, from first to last.
To configure authentication order in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 4.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 4: Authentication
Order Configuration Details
| Task |
Your Action |
Configure the authentication order.
|
- Click Add new entry next to Profile.
- Click Authentication Order next to
Profile.
- Click Add new entry next to Accounting
Order.
- In the New authentication-order window,
select the order in which the JUNOS Software tries different authentication
methods when verifying that a client can access the router.
|
Configuring the Authorization Order (NSM Procedure)
To configure authorization order in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 5.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 5: Authorization
Order Configuration Details
| Task |
Your Action |
Configure the authorization order.
|
- Click Add new entry next to Profile.
- Click Authorization Order next to
Profile.
- Click Add new entry next to Authorization
Order.
- In the New authorization-order window,
select the authorization order.
|
Configuring the L2TP Client (NSM Procedure)
To configure the Layer 2 Tunneling Protocol (L2TP) Client
in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 6.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 6: Client Configuration Details
| Task |
Your Action |
Configure the client.
|
- Click Add new entry next to Profile.
- Click Client next to Profile.
- Click Add new entry next to Client.
- In the Name box, enter the client
name.
- In the Comment box, enter the comment.
- In the Chap Secret box, enter the
secret key associated with a peer.
- In the pap password box, enter the
Password Authentication Protocol (PAP) password.
|
Configure a client group.
|
- Click Client Group next to client.
- Click Add new entry next to Client
Group.
- In the New client-group window, enter
the client group.
|
Configure a firewall user.
|
- Click Firewall User next to client.
- In the Comment box, enter the comment.
- In the Password box, enter the password.
|
Configure PPP properties for a client profile.
|
- Click Ppp next to client.
- Select ike to configure an IKE access
profile.
- In the Comment box, enter the comment.
- Select Initiate Dead Peer Detection to detect inactive peers on dynamic IPSec tunnels.
- In the Interface Id box, enter the
interface identifier.
- Click Allowed Proxy Pair next to
Ike.
- Click Add new entry next to Allowed
Proxy Pair.
- In the Local box, enter the network
address of the local peer.
- In the Remote box, enter the network
address of the remote peer.
- In the Comment box, enter the comment.
- Click Pre Shared Key next to Ike.
- Select pre-shared-key to configure
the key used to authenticate a dynamic peer during IKE phase 1 negotiation
and select the key.
- In the Comment box, enter the comment.
- Click Ascii Text next to Pre Shared
key.
- In the ascii-text box, enter the
string.
- Select Ike-policy to authenticate
dynamic peers during IKE negotiation and select the policy name.
|
Configuring the Client Filter Name (NSM Procedure)
To configure restrictions on client names in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 10.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 7: Client Filter
Name Configuration Details
| Task |
Your Action |
Configure the restrictions on client names.
|
- Click Add new entry next to Profile.
- Click Client Name Filter next to
profile.
- In the Comment box, enter the comment.
- In the Domain Name box, enter the
domain name.
- In the Separator box, enter the separator
character in domain name.
- From the Count list, select the number
of separator instances.
Range: 0 through 255
|
Configuring the LDAP Options (NSM Procedure)
To configure Lightweight Directory Access Protocol (LDAP)
options in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 8.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 8: Ldap Options Configuration Details
| Task |
Your Action |
Configure lightweight directory access protocol options.
|
- Click Add new entry next to Profile.
- Click Ldap Options next to profile.
- In the Comment box, enter the comment.
- From the Revert Interval list, select
the amount of time the router waits after a server has become unreachable.
Range: 60 through 4294967295
Default: 600
- In the Base Distinguished Name box,
enter the suffix when assembling user distinguished name (DN) or base
DN under which to search for user DN.
|
Derive user distinguished name from common-name and base-distinguished-name.
|
- Click Assemble next to Ldap Options.
- Select one of the following:
- assemble—To derive user distinguished
name from common-name and base-distinguished-name.
- In the Comment box, enter the comment.
- In the Common Name box, enter the
common name.
- search—To search for user's
distinguished name.
- In the Comment box, enter the comment.
- In the Search Filter box, enter
the filter to use in search.
- Click Admin Search next to Search.
- In the Comment box, enter the comment.
- In the Distinguished Name box, enter
the user distinguished name.
- In the Password box, enter the password.
|
Configuring the LDAP Server (NSM Procedure)
To configure Lightweight Directory Access Protocol (LDAP)
server in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 9.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 9: Ldap Server Configuration
Details
| Task |
Your Action |
Configure LDAP server.
|
- Click Add new entry next to Profile.
- Click Ldap Server next to profile.
- Click Add new entry next to Ldap
Server.
- In the Name box, enter the name of
the server.
- In the Comment box, enter the comment.
- From the Port list, select the port
number on which to contact the RADIUS server (LDAP server)
- In the Source Address box, enter
a valid IPv4 address configured on one of the router interfaces. On
M Series routers only, the source address can be an IPv6 address and
the UDP source port is 514.
- From the Routing Instances list,
select the routing instance name.
- From the Retry list, select the number
of times that the router is allowed to attempt to contact a RADIUS
server.
Range: 1 through 10
Default: 3
- From the Timeout list, select the
amount of time that the local router waits to receive a response from
a RADIUS server.
Range: 3 through 90
Default: 5
|
Configuring the Provisioning Order (NSM Procedure)
To configure the provisioning order in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 10.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 10: Provisioning
Order Configuration Details
| Task |
Your Action |
Configure the provisioning order.
|
- Click Add new entry next to Profile.
- Click Provisioning Order next to
profile.
- Click Add new entry next to Provisioning
Order.
- In the New provisioning-order window,
select the order in which provisioning mechanisms are used.
|
Configuring RADIUS Parameters for AAA Subscriber Management
(NSM Procedure)
You can specify the RADIUS parameters for the subscriber
access manager feature. You can specify the IP addresses of the RADIUS
servers used for authentication and accounting, options that provide
configuration information for the RADIUS servers, and how RADIUS attributes
are used.
To configure radius parameters for AAA subscriber management
in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 11.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 11: Radius Parameter
Configuration Details
| Task |
Your Action |
Configure the RADIUS parameters.
|
- Click Add new entry next to Profile.
- Click Radius next to Profile.
- In the Comment box, enter the comment.
|
Specify a list of the RADIUS accounting servers used
for accounting for Dynamic Host Configuration Protocol (DHCP), Layer
2 Tunneling Protocol (L2TP), and Point-to-Point Protocol (PPP) clients.
|
- Click Attributes next to Radius.
- In the Comment box, enter the comment.
|
Configure the router to exclude the specified attributes
from the specified type of RADIUS message.
|
- Click Exclude next to Radius.
- In the Comment box, enter the comment.
- From the listed RADIUS attribute type, select the attributes
to be excluded.
RADIUS attribute types are:
- accounting-authentic—RADIUS
attribute 45, Acct-Authentic
- accounting-delay-time—RADIUS
attribute 41, Acct-Delay-Time
- accounting-session-id—RADIUS
attribute 44, Acct-Session-Id
- accounting-terminate-cause—RADIUS
attribute 49, Acct-Terminate-Cause
- called-station-id—RADIUS attribute
30, Called-Station-Id
- calling-station-id—RADIUS attribute
31, Calling-Station-Id
- class—RADIUS attribute 25,
Class
- dhcp-gi-address—Juniper VSA
26-57, DHCP-GI-Address
- dhcp-mac-address—Juniper VSA
26-56, DHCP-MAC-Address
- Dhcp Options— Excludes RADIUS
attribute 26-55
- event-timestamp—RADIUS attribute
55, Event-Timestamp
- framed-ip-address—RADIUS attribute
8, Framed-IP-Address
- framed-ip-netmask—RADIUS attribute
9, Framed-IP-Netmask
- input-filter—Juniper VSA 26-10,
Ingress-Policy-Name
- input-gigapackets—Juniper VSA
26-42, Acct-Input-Gigapackets
- input-gigawords—RADIUS attribute
52, Acct-Input-Gigawords
- interface-description—Juniper
VSA 26-53, Interface-Desc
- nas-identifier—RADIUS attribute
32, NAS-Identifier
- nas-port—RADIUS attribute 5,
NAS-Port
- nas-port-id—RADIUS attribute
87, NAS-Port-Id.
- nas-port-type—RADIUS attribute
61, NAS-Port-Type
- output-filter—Juniper VSA 26-11,
Egress-Policy-Name
- output-gigapackets—Juniper
VSA 25-43, Acct-Output-Gigapackets
- output-gigawords—RADIUS attribute
53, Acct-Output-Gigawords
|
Configure the router to ignore the specified attributes
in RADIUS Access-Accept messages.
|
- Click Ignore next to client.
- In the Comment box, enter the comment.
- Select the following check boxes to ignore the specified
attributes:
- output-filter—Egress-Policy-Name
(VSA 26-11)
- input-filter—Ingress-Policy-Name
(VSA 26-10)
- framed-ip-netmask—Framed-IP-Netmask
(RADIUS attribute 9
- logical-system-routing-instance—Virtual-Router
(VSA 26-1)
|
Specify a list of the RADIUS authentication servers used
to authenticate DHCP, L2TP, and PPP clients.
|
- Click Authentication Server next
to Radius.
- Click Add new entry next to Authentication
Server.
- In the New authentication-server window,
enter the IPv4 address.
|
Configure the options used by RADIUS authentication and
accounting servers.
|
- Click Options next to Radius.
- In the Comment box, enter the comment.
- Select the Ethernet Port Type Virtual check box to specify a port type of virtual.
- From the Interface Description Format list, select the information that is included in or omitted from
the interface description that the router passes to RADIUS for inclusion
in the RADIUS attribute 87 (NAS-Port-Id).
Select one of the following:
- sub-interface—To specify the
subinterface.
- adapter—To specify the adapter.
- In the Nas Identifier box, enter
a string in the range from 1 to 64 characters.
- From the Accounting Session Id Format list, select the format the router uses to identify the accounting
session. Select one of the following:
- decimal—To use the decimal
format.
- description—To use the generic
format, in the form jnpr interface-specifier:subscriber-session-id.
Default: decimal
- From the Revert Interval list, select
the amount of time the router waits after a server has become unreachable.
Range: 60 through 4294967295 seconds
Default: 600 seconds
- Select the vlan-nas-port-stacked-format check box to configure RADIUS attribute 5 (NAS-Port) to include
the S-VLAN ID, in addition to the VLAN ID, for subscribers on Ethernet
interfaces.
|
Configure the RADIUS client to use the extended format
for RADIUS attribute 5 (NAS-Port) and specify the width of the fields
in the NAS-Port attribute.
|
- Click Nas Port Extended Format next
to Options.
- In the Comment box, enter the comment.
- From the Slot Width list, select
the number of bits in the slot field.
- From the Adapter Width list, select
the number of bits in the adapter field.
- From the Port Width list, select
the number of bits in the port field.
- From the Stacked Vlan Width list,
select the number of bits in the SVLAN ID field.
- From the Vlan Width list, select
the number of bits in the VLAN ID field.
|
Configuring the RADIUS Parameters (NSM Procedure)
You can specify the options used by the RADIUS authentication
and accounting servers.
To configure the radius parameters in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 12.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
 |
Note:
To create a profile, the device should be in the in-device
policy mode.
|
Table 12: Radius Parameters
Configuration Details
| Task |
Your Action |
Configure the radius parameters.
|
- Click Add new entry next to Profile.
- Click Radius Options next to Profile.
- In the Comment box, enter the comment.
- From the Revert Interval list, select
the amount of time the router waits after a server has become unreachable.
Default: 600 seconds
|
Configuring the RADIUS for Subscriber Access Management, L2TP,
or PPP (NSM Procedure)
You can configure RADIUS for subscriber access management,
L2TP, or PPP. The servers are tried in order and in a round-robin
fashion until a valid response is received from one of the servers
or until all the configured retry limits are reached.
To configure the radius server in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 13.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 13: Radius Server Configuration
Details
| Task |
Your Action |
Configure the RADIUS servers.
|
- Click Add new entry next to Profile
- Click Radius Server next to Profile.
- In the Name box, enter the profile
name.
- In the Comment box, enter the comment.
- From the Port list, select the port
number on which to contact the RADIUS server.
Default: 1812 (as specified in RFC 2865)
- In the Secret box, enter the password
to use with the RADIUS server. The secret password used by the local
router must match that used by the server.
- From the Timeout list, select the
amount of time that the local router waits to receive a response from
a RADIUS server.
Range: 3 through 90 seconds
Default: 3 seconds
- From the Retry list, select the number
of times that the router is allowed to attempt to contact a RADIUS
server.
Range: 1 through 10
Default: 3
- In the Source Address box, enter
a valid IPv4 address configured on one of the router interfaces.
- From the Routing Instance list, select
the routing instance name.
|
Configuring Session Limit (NSM Procedure)
To configure the timeout limit in NSM:
- In the NSM navigation tree, select Device Manager > Devices.
- Click the Device Tree tab,
and then double-click the device to select it.
- Click the Configuration tab.
In the configuration tree, expand Access.
- Select Profile.
- Add or modify settings as specified in Table 14.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 14: Session Limit Configuration
Details
| Task |
Your Action |
Configure the timeout interval.
|
- Click Add new entry next to Profile.
- Click Session Options next to Profile.
- In the Comment box, enter the comment.
- From the Client Idle Timeout list,
select the time in minutes of idleness after which access is denied.
Range: 1 through 255 minutes
- From the Client Session Timeout list,
select the time in minutes since initial access after which access
is denied.
|
Configure a client group.
|
- Click Client Group next to Session
Option.
- Click Add new entry next to Client
Group.
- In the New client-group window, enter
the client group.
|
Published: 2009-08-23