ZyWALL 10 Internet Security Gateway
PPTP
D
Access Concentrator) and the PPTP user. The PNS is the box that hosts both the PPP and the PPTP stacks
and forms one end of the PPTP tunnel. The PAC is the box that dials/answers the phone calls and relays the
PPP frames to the PNS. The PPTP user is not necessarily a PPP client (can be a PPP server too). Both the
PNS and the PAC must have IP connectivity; however, the PAC must in addition have dial-up capability.
The phone call is between the user and the PAC and the PAC tunnels the PPP frames to the PNS. The PPTP
user is unaware of the tunnel between the PAC and the PNS.
Diagram 4 PPTP Protocol Overview
Microsoft includes PPTP as a part of the Windows OS. In Microsoft’s implementation, the PC, and hence the
ZyWALL, is the PNS that requests the PAC (the ANT) to place an outgoing call over AAL5 to an RFC 2364
server.
Control & PPP connections
Each PPTP session has distinct control connection and PPP data connection.
Call Connection
The control connection runs over TCP. Similar to L2TP, a tunnel control connection is first established
before call control messages can be exchanged. Please note that a tunnel control connection supports
multiple call sessions.
The following diagram depicts the message exchange of a successful call setup between a PC and an ANT.
Diagram 5 Example Message Exchange between PC and an ANT
PPP Data Connection
The PPP frames are tunneled between the PNS and PAC over GRE (General Routing Encapsulation, RFC
1701, 1702). The individual calls within a tunnel are distinguished using the
Call ID
field in the GRE
header.
Summary of Contents for ZyWALL 10
Page 1: ...ZyWALL 10 Internet Security Gateway User s Guide Version 3 20 November 2000...
Page 6: ...ZyWALL 10 Internet Security Gateway vi CE Doc...
Page 22: ......
Page 26: ......
Page 30: ......
Page 73: ......
Page 96: ......
Page 138: ......
Page 161: ......
Page 169: ......
Page 181: ......
Page 195: ......
Page 203: ......
Page 222: ......
Page 226: ......