想要通過在賬戶裏配置access-limit限製L2TP VPN賬戶使用人數。access-limit需要通過PPP的計費來實現。但是發現如果兩個用戶用同一個賬號撥入,顯示的用戶數還是隻有一個。
配置如下:
#
l2tp-group 1 mode lns
allow l2tp virtual-template 1
undo tunnel authentication
#
l2tp enable
#
interface Virtual-Template1
ppp authentication-mode chap
ppp account-statistics enable
ip address 192.168.200.1 255.255.255.0
#
local-user h3c class network
password cipher $c$3$6P3rkJeI+koDYSgH/z22BGAoWJKKbQ==
access-limit 1
service-type ppp
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
authorization-attribute ip 192.168.100.2
兩台設備同時撥入後信息如下:
<H3C>display ppp access-user username h3c
Basic:
Interface: VA0
User ID: 0x28000001
Username: h3c
Domain: -
IP address: 192.168.100.2
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:09:04:388
Accounting start time: 2017-05-20 21:09:04:394
Online time(hh:mm:ss): 00:04:00
Accounting state: Accounting
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 1674/130615
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
Basic:
Interface: VA1
User ID: 0x28000002
Username: h3c
Domain: -
IP address: 192.168.100.2
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:12:59:442
Accounting start time: -
Online time(hh:mm:ss): 00:00:05
Accounting state: Stop
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 0/0
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
<H3C>dis local-user user-name h3c class network
Total 1 local users matched.
Network access user h3c:
State: Active
Service type: PPP
Access limit: Enabled Max access number: 1
Current access number: 1
User group: system
Bind attributes:
Authorization attributes:
Work directory: cfa0:
User role list: network-admin, network-operator
IP address: 192.168.100.2
可以看到,一個計費狀態是 Accounting state: Stop,一個是Accounting state: Accounting。
如果是因為針對單一IP進行計費導致的,那麼如果讓兩個用戶獲取到不同地址,效果也是一樣的。
<H3C>dis ppp access-user username h3c
Basic:
Interface: VA0
User ID: 0x28000001
Username: h3c
Domain: -
IP address: 192.168.100.2
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:25:58:685
Accounting start time: -
Online time(hh:mm:ss): 00:00:43
Accounting state: Stop
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 0/0
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
Basic:
Interface: VA1
User ID: 0x28000002
Username: h3c
Domain: -
IP address: 192.168.100.3
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:26:09:502
Accounting start time: 2017-05-20 21:26:09:511
Online time(hh:mm:ss): 00:00:33
Accounting state: Accounting
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 195/14653
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
<H3C>display local-user user-name h3c class network
Total 1 local users matched.
Network access user h3c:
State: Active
Service type: PPP
Access limit: Enabled Max access number: 1
Current access number: 1
User group: system
Bind attributes:
Authorization attributes:
Work directory: cfa0:
User role list: network-admin, network-operator
請問一下,這種情況是什麼原因?
(0)
最佳答案
親~登錄後才可以操作哦!
確定你的郵箱還未認證,請認證郵箱或綁定手機後進行當前操作
舉報
×
侵犯我的權益
×
侵犯了我企業的權益
×
抄襲了我的內容
×
原文鏈接或出處
誹謗我
×
對根叔社區有害的內容
×
不規範轉載
×
舉報說明
不客氣