14.1.2.11.4 Connection with L2TP Client
297
In case of an expensive dialup connection (e.g. ISDN), using
DPD can become pretty expensive. Data is sent every 30
seconds, so the connection will stay online all the time.
Perfect forward secrecy
Perfect forward secrecy (PFS) for phase 2 enhances the security of a VPN connection.
An intruder who manages to access the preshared key or the private key of a VPN
will not be able to decrypt a recorded VPN session when PFS is active. Setting PFS
to "optional" is not recommended, but may be necessary for interoperability with other
IPSEC implementations.
ESP-Proposals
The phase 2 proposals determine acceptable ciphers and hash-algorithms for the
actual data transmission.
If no proposals have been entered here, all proposals SX-GATE
supports are accepted.
14.1.2.11.4-D
Connection
Connect
Here you can enable or disable the VPN connection.
wait for incoming connection
Here, SX-GATE waits for the peer to establish the connection.
disabled
This setting will deactivate the corresponding VPN connection.
MacOS and iPhone compatibility
The builtin L2TP clients of MacOS X and iPhone use a random source port instead of
port 1701 only. The IPSec tunnel will be extended if you enable this switch.
The iPhone allows only preshared keys for authentication. You
might want to configure a second L2TP connection to support
both, preshared key connections with iPhones and certificate
based connections with other clients.