Page 266 / 351 Scroll up to view Page 261 - 265
266
set ppp module [vccn] configure-max
integer
Specifies the maximum number of unacknowledged configuration requests that your Neto-
pia Gateway will send. The integer argument can be any number between 1 and 20.
set ppp module [vccn] terminate-max
integer
Specifies the maximum number of unacknowledged termination requests that your Netopia
Gateway will send before terminating the PPP link. The integer argument can be any num-
ber between 1 and 10.
set ppp module [vccn] restart-timer
integer
Specifies the number of seconds the Netopia Gateway should wait before retransmitting a
configuration or termination request. The integer argument can be any number between 1
and 30.
set ppp module [vccn] connection-type
{ instant-on | always-on }
Specifies whether a PPP connection is maintained by the Netopia Gateway when it is
unused for extended periods. If you specify
always-on
, the Netopia Gateway never shuts
down the PPP link. If you specify
instant-on
, the Netopia Gateway shuts down the PPP
link after the number of seconds specified in the
time-out
setting (below) if no traffic is
moving over the circuit.
set ppp module [vccn] time-out
integer
If you specified a connection type of
instant-on
, specifies the number of seconds, in the
range 30 - 3600, with a default value of 300, the Netopia Gateway should wait for commu-
nication activity before terminating the PPP link.
Configuring Port Authentication.
You can use the following command to specify how
your Netopia Gateway should respond when it receives an authentication request from a
remote peer.
The settings for port authentication on the local Netopia Gateway must match the authenti-
cation that is expected by the remote peer. For example, if the remote peer requires CHAP
authentication and has a name and CHAP secret for the Netopia Gateway, you must enable
Page 267 / 351
267
CONFIG Commands
CHAP and specify the same name and secret on the Netopia Gateway before the link can
be established.
set ppp module [vccn] port-authentication
option [ off | on | pap-only | chap-only ]
Specifying
on
turns both PAP and CHAP on, or you can select PAP or CHAP. Specify the
username
and
password
when port authentication is turned on (both CHAP and PAP,
CHAP or PAP.) Authentication must be enabled before you can enter other information.
set ppp module [vccn] port-authentication username
username
The
username
argument is 1 – 255 alphanumeric characters. The information you enter
must match the username configured in the PPP peer's authentication database.
set ppp module [vccn] port-authentication password
password
The
password
argument is 1 – 128 alphanumeric characters. The information you enter
must match the password used by the PPP peer.
Ethernet Port Settings
set ethernet ethernet A mode { auto | 100M-full | 100M-full-fixed |
100M-half-fixed | 10M-full-fixed | 10M-half-fixed |
100M-half | 10M-full | 10M-half }
Allows mode setting for the ethernet port. Only supported on units without a LAN switch, or
dual ethernet products (338x). In the dual ethernet case, “ethernet B” would be specified
for the WAN port. The default is
auto
.
Command Line Interface Preference Settings
You can set command line interface preferences to customize your environment.
set preference verbose { on | off }
Specifies whether you want command help and prompting information displayed. By
default, the command line interface verbose preference is turned off. If you turn it on, the
command line interface displays help for a node when you navigate to that node.
Page 268 / 351
268
set preference more
lines
Specifies how many lines of information you want the command line interface to display at
one time. The lines argument specifies the number of lines you want to see at one time.
The range is 1-65535. By default, the command line interface shows you 22 lines of text
before displaying the prompt:
More …[y|n] ?
.
If you enter 1000 for the
lines
argument, the command line interface displays information
as an uninterrupted stream (which is useful for capturing information to a text file).
Page 269 / 351
269
CONFIG Commands
Port Renumbering Settings
If you use NAT pinholes to forward HTTP or telnet traffic through your Netopia Gateway to
an internal host, you must change the port numbers the Netopia Gateway uses for its own
configuration traffic. For example, if you set up a NAT pinhole to forward network traffic on
Port 80 (HTTP) to another host, you would have to tell the Netopia Gateway to listen for
configuration connection requests on a port number other than 80, such as 6080.
After you have changed the port numbers the Netopia Gateway uses for its configuration
traffic, you must use those port numbers instead of the standard numbers when configur-
ing the Netopia Gateway. For example, if you move the router's Web service to port
“6080” on a box with a system (DNS) name of “superbox”, you would enter the URL
http:/
/superbox:6080
in a Web browser to open the Netopia Gateway graphical user interface.
Similarly, you would have to configure your telnet application to use the appropriate port
when opening a configuration connection to your Netopia Gateway.
set servers web-http [ 1 - 65534 ]
Specifies the port number for HTTP (web) communication with the Netopia Gateway.
Because port numbers in the range 0-1024 are used by other protocols, you should use
numbers in the range 1025-65534 when assigning new port numbers to the Netopia Gate-
way web configuration interface. A setting of
0
(zero) will turn the server off.
set servers telnet-tcp [ 1 - 65534 ]
Specifies the port number for telnet (CLI) communication with the Netopia Gateway.
Because port numbers in the range 0-1024 are used by other protocols, you should use
numbers in the range 1025-65534 when assigning new port numbers to the Netopia Gate-
way telnet configuration interface. A setting of
0
(zero) will turn the server off.
NOTE:
You cannot specify a port setting of
0
(zero) for both the web and telnet ports
at the same time. This would prevent you from accessing the Gateway.
Page 270 / 351
270
Security Settings
Security settings include the Firewall and IPSec parameters. All of the security functionality
is keyed.
Firewall Settings (for BreakWater Firewall)
set security firewall option [ ClearSailing | SilentRunning |
LANdLocked ]
The 3 settings for BreakWater are discussed in detail on page
page 125
.
SafeHarbour IPSec Settings
SafeHarbour VPN is a tunnel between the local network and another geographically dis-
persed network that is interconnected over the Internet. This VPN tunnel provides a
secure, cost-effective alternative to dedicated leased lines. Internet Protocol Security
(IPsec) is a series of services including encryption, authentication, integrity, and replay pro-
tection. Internet Key Exchange (IKE) is the key management protocol of IPsec that estab-
lishes keys for encryption and decryption. Because this VPN software implementation is
built to these standards, the other side of the tunnel can be either another Netopia unit or
another IPsec/IKE based security product. For VPN you can choose to have traffic authenti-
cated, encrypted, or both.
When connecting the Netopia unit in a telecommuting scenario, the corporate VPN settings
will dictate the settings to be used in the Netopia unit. If a parameter has not been speci-
fied from the other end of the tunnel, choose the default unless you fully understand the
ramifications of your parameter choice.
set security ipsec option (off) {on | off}
Turns on the SafeHarbour IPsec tunnel capability. Default is off. See
“IPSec” on page 130
for more information.
set security ipsec tunnels name "123"
The name of the tunnel can be quoted to allow special characters and embedded spaces.

Rate

4.7 / 5 based on 3 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top