想要通过在账户里配置access-limit限制L2TP VPN账户使用人数。access-limit需要通过PPP的计费来实现。但是发现如果两个用户用同一个账号拨入,显示的用户数还是只有一个。
配置如下:
#
l2tp-group 1 mode lns
allow l2tp virtual-template 1
undo tunnel authentication
#
l2tp enable
#
interface Virtual-Template1
ppp authentication-mode chap
ppp account-statistics enable
ip address 192.168.200.1 255.255.255.0
#
local-user h3c class network
password cipher $c$3$6P3rkJeI+koDYSgH/z22BGAoWJKKbQ==
access-limit 1
service-type ppp
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
authorization-attribute ip 192.168.100.2
两台设备同时拨入后信息如下:
<H3C>display ppp access-user username h3c
Basic:
Interface: VA0
User ID: 0x28000001
Username: h3c
Domain: -
IP address: 192.168.100.2
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:09:04:388
Accounting start time: 2017-05-20 21:09:04:394
Online time(hh:mm:ss): 00:04:00
Accounting state: Accounting
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 1674/130615
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
Basic:
Interface: VA1
User ID: 0x28000002
Username: h3c
Domain: -
IP address: 192.168.100.2
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:12:59:442
Accounting start time: -
Online time(hh:mm:ss): 00:00:05
Accounting state: Stop
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 0/0
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
<H3C>dis local-user user-name h3c class network
Total 1 local users matched.
Network access user h3c:
State: Active
Service type: PPP
Access limit: Enabled Max access number: 1
Current access number: 1
User group: system
Bind attributes:
Authorization attributes:
Work directory: cfa0:
User role list: network-admin, network-operator
IP address: 192.168.100.2
可以看到,一个计费状态是 Accounting state: Stop,一个是Accounting state: Accounting。
如果是因为针对单一IP进行计费导致的,那么如果让两个用户获取到不同地址,效果也是一样的。
<H3C>dis ppp access-user username h3c
Basic:
Interface: VA0
User ID: 0x28000001
Username: h3c
Domain: -
IP address: 192.168.100.2
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:25:58:685
Accounting start time: -
Online time(hh:mm:ss): 00:00:43
Accounting state: Stop
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 0/0
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
Basic:
Interface: VA1
User ID: 0x28000002
Username: h3c
Domain: -
IP address: 192.168.100.3
IPv6 address: -
IPv6 PD prefix: -
VPN instance: -
Access type: L2TP
Authentication type: CHAP
AAA:
Authentication state: Authenticated
Authorization state: Authorized
Realtime accounting switch: Closed
Realtime accounting interval: -
Login time: 2017-05-20 21:26:09:502
Accounting start time: 2017-05-20 21:26:09:511
Online time(hh:mm:ss): 00:00:33
Accounting state: Accounting
Idle cut: 0 sec 0 byte
Session timeout: -
Time remained: -
Byte remained: -
Redirect WebURL: -
ACL&QoS:
User profile: -
User group profile: -
Inbound CAR: -
Outbound CAR: -
Flow Statistic:
IPv4 uplink packets/bytes: 195/14653
IPv4 downlink packets/bytes: 0/0
IPv6 uplink packets/bytes: 0/0
IPv6 downlink packets/bytes: 0/0
<H3C>display local-user user-name h3c class network
Total 1 local users matched.
Network access user h3c:
State: Active
Service type: PPP
Access limit: Enabled Max access number: 1
Current access number: 1
User group: system
Bind attributes:
Authorization attributes:
Work directory: cfa0:
User role list: network-admin, network-operator
请问一下,这种情况是什么原因?
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
不客气