
303509-A Rev 00 8-1
Chapter 8
Requirements Outside the ISP Network
Although the responsibility for configuring network elements outside the Dial
VPN service provider network rests with others, you still need to communicate the
Dial VPN system requirements to them. These requirements include:
• Ensuring that the remote node (PC or dial-in router) is configured to use PPP
and to allow the RAC to assign IP and IPX network and node addresses to it.
• Making sure that the RADIUS server on the home network is configured with
the information necessary to authenticate the users who want to dial in to the
network on which it resides. BaySecure Access Control (BSAC) is the Bay
Networks remote RADIUS server software that supports Dial VPN. The
RADIUS server and the RADIUS client on the gateway must share the same
primary secret.
• For Layer 3 tunnels, configuring the CPE router on the home (destination)
network for frame relay or PPP, and -- on Bay Networks routers -- configuring
an adjacent host and (for frame relay) appropriate DLCIs. For any CPE router,
there must also exist a static route from the CPE router to the RADIUS client
on the gateway, and a static route to the remote node’s “supernet,” the network
to which the remote node’s user community connects.
Fulfilling this requirement ensures that responses from the corporate network
or third-party service provider to the remote node are correctly routed.
Because of router requirements, this step is required for Bay Networks
routers. Routers from other manufacturers may have other requirements. The
following sections provide more information about configuring the static
route and adjacent host information.
• For Layer 2 tunnels, configuring the CPE router as a Layer 2 tunnel end point
(LNS).
Komentarze do niniejszej Instrukcji