15 Configuration of an L2TP IPSec VPN client
453
15 Configuration of an L2TP IPSec VPN client
15.1 Microsoft Windows
This howto describes the configuration of an L2TP IPSec VPN to SX-GATE, using
the builtin IPSec implementation of Microsoft Windows. Screenshots have been taken
from Windows XP Professional, however the configuration in other windows releases
supporting L2TP IPSec is quite similar.
Depending on the Windows release you are using, the
screenshots in this howto may differ from the screens you will
encounter.
Prerequisits for the windows client:
•
Manual configuration: Windows 2000 or newer
•
Automatic configuration: Windows XP SP2 or newer and authentication using
certificates.
•
If NAT traversal is required: On the systems running Windows XP (up to SP1)
or Windows 2000 the Mircosoft patch Q818043 has to be applied
•
Preshared Key authentication is not supported with Windows 2000
The SX-GATE VPN server should be already configured. It is highly recommended to
use SX-GATE's wizard "L2TP IPSec VPN" from the "Wizards" menu. If you are using
X.509 certificates for authentication, please make sure to have the required key and
certificate files at hands.
On the last screen of the "L2TP IPSec VPN" wizard you will find
a note which tells you how to issue certificates. Please rerun the
wizard if you missed that hint.
Basically the L2TP-IPSec connectivity is provided by two different SX-GATE services:
IPSec VPN
The IPSec connection provides a secure tunnel for the L2TP protocol it
encapulates.
Only L2TP packets (UDP port 1701) will be accepted within the IPSec tunnel.
The IPSec tunnel must be authenticated with either a preshared key or by X.509
certificates.
L2TP server
Similar to a dial-up connection, L2TP is based on the PPP protocol.