You must add the
ProhibitIpSec
registry value to each Windows XP-based endpoint computer of an
L2TP or IPSec connection to prevent the automatic filter for L2TP and IPSec traffic from being created.
When the
ProhibitIpSec
registry value is set to 1, your Windows XP-based computer does not create
the automatic filter that uses CA authentication. Instead, it checks for a local or Active Directory IPSec
policy.
Connecting to the L2TP VPN
·
Connect to your ISP.
·
Start the VPN connection that you configured in the previous procedure.
·
Enter your L2TP VPN User Name and Password.
·
Select Connect.
·
In the connect window, enter the User Name and Password you use to connect to your dial-up network
connection.
This user name and password is not the same as your VPN user name and password.
RADIUS authentication for PPTP and L2TP VPNs
If you have RADIUS servers installed, you can configure the DFL-500 to use RADIUS for authenticating
PPTP and L2TP users. To configure RADIUS authentication, you must add the IP addresses of your RADIUS
servers to the DFL-500 VPN configuration and then turn on RADIUS support for PPTP and L2TP.
If you have added PPTP and L2TP user names and passwords and configured RADIUS support, when a
PPTP or L2TP user connects to a DFL-500, the user name and password is checked against the DFL-500
PPTP or L2TP user name and password list. If a match is not found locally, the DFL-500 contacts the
RADIUS server for authentication.
RADIUS authentication is not supported by Windows 98 clients.
Adding RADIUS server addresses
You can install your RADIUS server on the Internet or on the internal network. No special DFL-500
configuration is required for RADIUS support for PPTP and L2TP other than what is described below. If you
want non-VPN users to be able to connect to a RADIUS server installed on your internal network, you must
add firewall policies to grant access to the server from the Internet.
To configure the DFL-500 for RADIUS authentication:
·
Go to
VPN > RADIUS
.
·
Enter the server name or IP address of your primary RADIUS server.
·
Enter the primary RADIUS server secret.
·
Optionally enter the server name or IP address and secret for your secondary RADIUS server.
·
Select Apply.
DFL-500 User Manual
85
Содержание DFL-500
Страница 1: ...DFL 500 V2 27 User Manual D Link Systems Inc DFL 500 User Manual 1 ...
Страница 102: ...DFL 500 User Manual 102 ...
Страница 136: ...DFL 500 User Manual 136 ...
Страница 140: ...Registration Register the D Link DFL 500 Office Firewall online at http www dlink com sales reg DFL 500 User Manual 140 ...