
303509-A Rev 00 5-1
Chapter 5
Configuring TMS and Security
for erpcd Networks
In a Dial VPN network, tunnel users are authenticated by a RADIUS server
running BaySecure Access Control (BSAC) on the remote network, although the
tunnel management database resides at the service provider network.
All administration and configuration of the tunnel happens at the service
provider’s site. An administrator at the service provider site must configure the
tunnel with various attributes: its destination IP address, the security protocols it
supports, its password, and so on. These attributes are stored in the tunnel
management system (TMS) database.
Dial VPN offers two ways of managing and using the TMS database:
erpcd-based, described in this chapter, and RADIUS-only, described in Chapter 6
.
In both of these methods, the TMS database resides on the service provider
network and specifies:
• Where dial-in user authentication takes place
• Which servers authenticate dial-in users
• Where the other end point of the tunnel is (the NAS is the first end point) --
either the gateway router for a Layer 3 tunnel or the LNS at the home network
for a Layer 2 tunnel
Komentarze do niniejszej Instrukcji