193
The iPhone allows only preshare keys for authentication. You
might want to configure a second L2TP connection to support
both, preshared key connections with iPhones and certificate
based connections with other clients. This second connection
must be added later in menu "Modules > Network > Interfaces"
for "ipsec0".
For certificate based authentication the SX-GATE VPN server
certificate must have been issued with the "Subject alternativ
names" set to the IP or DNS name which has been configured
as server name in the MacOS client.
Compatibility for old Windows clients
If the builtin client of Windows 2000 or Windows XP before Servicepack 2 is in use,
you will either have to update them with Microsoft update Q818043 or enable this
compatibility switch. The switch will set the port of the tunnel's local end to 0.
L2TP IP addresses
IP addresses assigned to L2TP clients
Insert the IP addresses which SX-GATE will assign to the peers. The IPs must no be
in use elsewhere. If possible, you should enter IPs from the network the L2TP client
wants to connect with. This network has to be directly connected to SX-GATE.
The number of IP addresses specified here determines the
maximum number of concurrent L2TP connections.
You can either add single IPs or whole blocks of addresses. A block of addresses is
specified by a network address with its corresponding netmask. If for example the LAN
network is 192.168.0.0/24, the entry 192.168.0.160/27 will add the 32 IP addresses
from the range 192.168.0.160 to 192.168.0.191.
The address ranges must not include network or broadcast
addresses of a local ethernet, except for the network and
broadcast addresses of a class C network (*.0 and *.255). The
system will exclude these automatically.