14
8/11/2019 How to Configure l2tp Over Ipsec http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 1/14 2007 May 1 L2TP over ISPEC For roaming user VPN-Gateway 1.1.1.1 Road Warrior Windows XP SP2 Company Network 192.168.123.0/24 5.5.5.60 L2TP-over-IPSEC Tunnel DFL-1600

How to Configure l2tp Over Ipsec

Embed Size (px)

Citation preview

Page 1: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 1/14

2007 May 1

L2TP over ISPEC

For roaming user

VPN-Gateway

1.1.1.1

Road Warrior

Windows XP

SP2

Company

Network

192.168.123.0/24

5.5.5.60

L2TP-over-IPSEC Tunnel

DFL-1600

Page 2: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 2/14

2007 May 2

L2TP over ISPEC

For roaming user

Page 3: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 3/14

2007 May 3

L2TP over ISPEC

For roaming user DFL 1600 settings 1/7

1Create the IP pools, L2tp-server’s IP address and

change the IP of wan1 and lan1, subnet mask of

lan1 and wan1, under the Address Book

2Under Authentication Objects, create a

pre-share key for the usage of IPSEC

tunnel

Page 4: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 4/14

2007 May 4

L2TP over ISPEC

For roaming user DFL 1600 settings 2/7

3 Under the Interfaces, create the IPSEC

interface for roaming users.

1. Why I select the Local Network to wan1_ip ?

Because we shall let the remote roaming users

knowing the firewall is a final destination.Or you can set this value to all-nets , let the DFL

unit auto search suitable policy.

2. Due to we don’t know the roaming user address 

,we also let DFL unit auto search suitable policy.

Page 5: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 5/14

2007 May 5

L2TP over ISPEC

For roaming user DFL 1600 settings 3/7

4

Under the authentication, select the pre-

shared key “ipsec-  pre” that we created in

step 2

5In this scenario we have no use the Xauth feature.

Under the Routing  field, enable the function of

“Dynam ically Add Route To Remote Net..” 

Page 6: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 6/14

2007 May 6

L2TP over ISPEC

For roaming user DFL 1600 settings 4/7

6

Under IKE Settings:

IKEMode: Main (Mainmode)

DHGroup: 2

PFS: NoneSetupSAPer: Host (Per host)

DeadPeerDetection: Yes

NATTraversal: OnIfNeeded (Only if

needed) 

Disable Keep-alive feature

Under Advanced : AutoInterfaceNetworkRoute: No

Page 7: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 7/14

2007 May 7

L2TP over ISPEC

For roaming user DFL 1600 settings 5/7

7Under Interfaces  field, add L2TP server’s interface, below is a step-by-step settings.

Note the field of “Outer Interface Filter” shall set to IPSEC interface which is created at

STEP 3

Page 8: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 8/14

2007 May 8

L2TP over ISPEC

For roaming user DFL 1600 settings 6/7

8 Add Loc al User Database

 Add User Authent icat ion rule

Page 9: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 9/14

2007 May 9

L2TP over ISPEC

For roaming user DFL 1600 settings 7/7

9 Add Interface Grou pes, grouping the interface of L2TP and

LAN1 for easy setup.

Create IP Rules  set, allow bi-direction traffic between the

interfaces of L2TP and lan1.

Page 10: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 10/14

2007 May 10

L2TP over ISPEC

For roaming user Windows XP settings 1/3

1Checking the status of IPSEC servic e  on Windows XP to make sure the IPSEC service

is enabled.

Page 11: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 11/14

2007 May 11

L2TP over ISPEC

For roaming user Windows XP settings 2/3

1Under the Network Connections--->Create a new connection and following the procedure

as below to set it up.

Page 12: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 12/14

2007 May 12

L2TP over ISPEC

For roaming user Windows XP settings 2/3

2 After the wizard step by step settings, we shall adjust some advance value for fitting the

settings with DFL-1600

Page 13: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 13/14

2007 May 13

L2TP over ISPEC

For roaming user Confirmation 1/2

1On the Windows platform, we shall try to connect the DFL-1600 server and checking the

connection status and to see if we can get the IP address from L2TP server by using the

command tool “ipconfig” and “ping”.

Page 14: How to Configure l2tp Over Ipsec

8/11/2019 How to Configure l2tp Over Ipsec

http://slidepdf.com/reader/full/how-to-configure-l2tp-over-ipsec 14/14

2007 May 14

L2TP over ISPEC

For roaming user Confirmation 2/2

Under the Status field, select User Authentication Status