Configuration Guide
8. L2TP VPN Server
Version 7.2
55
Security Setup
8
L2TP VPN Server
The device supports L2TP VPN servers. With this feature, the client can connect to the
device from other locations using Windows dialer. To configure the L2TP VPN server, use
the following commands:
Table 8-1: L2TP VPN Servers
Command
Description
# configure data
Configuration of the L2TP server on data level.
(config-data)# l2tp-server
Configuration of L2TP server.
(conf-l2tps)# ppp authentication
mschap
Enable mschap authentication.
(conf-l2tps)# ppp authentication
mschapv2
Enable mschap version 2 authentication.
(conf-l2tps)# ipsec key
<password>
Enable IPSec with password <password>.
#
show data l2tp-server
Displays users connected to the L2TP server.
For users to connect to the device using L2TP, the users need to be configured. Use the
following commands to configure the users:
Table 8-2: L2TP VPN User Configuration
Command
Description
# configure data
Enter the data configuration menu.
(config-data)# user <user name>
password <password>
Configure a user with a name <user name> and
password <password>.
Some operating systems don't have “NAT traversal” (NAT-T) enabled by default. Depending
on network topology and in some cases, this is required.
In Windows 10 operating system, NAT traversal can be enabled by editing the registry
(regedit.exe):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent
A DWORD 32 type value named “AssumeUDPEncapsulationContextOnSendRule” should
be set to 2 to enable NAT traversal. If the parameter doesn’t exist, then assume it is set to
0, meaning that there is no connection to servers behind NAT. If the parameter exists, then
1 means a connection where VPN server is behind NAT, and 2 means a connection where
server and the client are behind NAT.
8.1
Configuration Example
This example configures an L2TP VPN server and a Windows 7 client to connect to the
server.
The following must be configured on the device that acts as an L2TP server:
l2tp-server
ip range 192.168.1.3 192.168.1.8
no ppp authentication pap
ppp authentication chap
Summary of Contents for Mediant 500L MSBR
Page 2: ......
Page 4: ...Mediant MSBRs 4 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 8: ...Mediant MSBRs 8 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 12: ...Mediant MSBRs 12 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 16: ...Mediant MSBRs 16 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 18: ...Mediant MSBRs 18 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 24: ...Mediant MSBRs 24 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 28: ...Mediant MSBRs 28 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 54: ...Mediant MSBRs 54 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 62: ...Mediant MSBRs 62 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 72: ...Mediant MSBRs 72 Document LTRT 31828 Security Setup This page is intentionally left blank...