Default: 10
9.5.4. PPTP/L2TP Clients
The PPTP and L2TP protocols are described in the previous section. In addition to being able to act
as a PPTP or L2TP server, NetDefendOS also offers the ability to act as a PPTP or L2TP clients.
This can be useful if PPTP or L2TP is preferred as the VPN protocol instead of IPsec. One D-Link
Firewall can act as a client and connect to another unit which acts as the server.
Client Setup
PPTP and L2TP shares a common approach to client setup which involves the following settings:
General Parameters
•
Name - A symbolic name for the client.
•
Interface Type - Specifies if it is a PPTP or L2TP client.
•
Remote Endpoint - The IP address of the remote endpoint. Where this is specified as a URL,
the prefix dns: must be precede it.
Names of Assigned Addresses
Both PPTP and L2TP utilizes dynamic IP configuration using the PPP LCP protocol. When
NetDefendOS receives this information, it is stored in symbolic host/network names. The settings
for this are:
•
Inner IP Address - The host name that is used for storing the assigned IP address. If this
network object exists and has a value which is not 0.0.0.0 then the PPTP/L2TP client will try to
get that one from the PPTP/L2TP server as the preferred IP.
•
Automatically pick name - If this option is enabled then NetDefendOS will create a host name
based on the name of the PPTP/L2TP interface, for example ip_PPTPTunnel1.
•
Primary/Secondary DNS Name - This defines the DNS servers from a list of predefined
network objects.
Note
A PPTP/L2TP server will not provide information such as gateway or broadcast
addresses, as this is not used with PPTP/L2TP tunnels. When using PPTP/L2TP, the
default route is normally routed directly across the PPTP/L2TP tunnel without a
specified gateway.
Authentication
•
Username - Specifies the username to use for this PPTP/L2TP interface.
•
Password - Specifies the password for the interface.
•
Authentication - Specifies which authentication protocol to use.
•
MPPE - Specifies if Microsoft Point-to-Point Encryption is used and which level to use.
If Dial On Demand is enabled then the PPTP/L2TP tunnel will not be set up until traffic is sent on
the interface. The parameters for this option are:
•
Activity Sense - Specifies if dial-on-demand should trigger on Send or Recv or both.
9.5.4. PPTP/L2TP Clients
Chapter 9. VPN
369
Summary of Contents for DFL-210 - NetDefend - Security Appliance
Page 24: ...1 3 NetDefendOS State Engine Packet Flow Chapter 1 NetDefendOS Overview 24...
Page 69: ...2 6 4 Restore to Factory Defaults Chapter 2 Management and Maintenance 69...
Page 121: ...3 9 DNS Chapter 3 Fundamentals 121...
Page 181: ...4 7 5 Advanced Settings for Transparent Mode Chapter 4 Routing 181...
Page 192: ...5 5 IP Pools Chapter 5 DHCP Services 192...
Page 282: ...6 7 Blacklisting Hosts and Networks Chapter 6 Security Mechanisms 282...
Page 300: ...mechanism 7 3 7 SAT and FwdFast Rules Chapter 7 Address Translation 300...
Page 301: ...7 3 7 SAT and FwdFast Rules Chapter 7 Address Translation 301...
Page 318: ...8 3 Customizing HTML Pages Chapter 8 User Authentication 318...
Page 322: ...ALG 9 1 5 The TLS Alternative for VPN Chapter 9 VPN 322...
Page 377: ...Management Interface Failure with VPN Chapter 9 VPN 377...
Page 408: ...10 4 6 SLB_SAT Rules Chapter 10 Traffic Management 408...
Page 419: ...11 5 HA Advanced Settings Chapter 11 High Availability 419...
Page 426: ...12 3 5 Limitations Chapter 12 ZoneDefense 426...
Page 449: ...13 9 Miscellaneous Settings Chapter 13 Advanced Settings 449...