Figure 24: L2TP Control Frame Encapsulated by IPSec
Figure 25 on page 279 is an L2TP data frame encapsulated by IPSec. The shaded area
shows the encrypted portion of the frame.
Figure 25: L2TP Data Frame Encapsulated by IPSec
Compatibility and Requirements
This section covers various compatibility issues and requirements for the L2TP/IPSec
traffic.
Client Software Supported
The L2TP/IPSec software supports the following client PC operating systems and L2TP
and IPSec applications:
•
Windows 2000 and Windows XP running built-in IPSec VPN software
•
Microsoft L2TP/IPSec VPN client for Windows NT, Windows 98, and Windows Me
•
SafeNet client software
•
Mac OS X version 10.3 or higher
Interactions with NAT
There are two ways that you can configure E Series routers to interact with Network
Address Translation (NAT) devices in the network:
•
Configure the router to run in NAT passthrough mode by using the
application
l2tp-nat-passthrough
command. For information, see “NAT Passthrough Mode” on
page 280
.
•
Configure the virtual router to enable NAT Traversal (NAT-T) by using the
ipsec option
nat-t
command. For information, see “NAT Traversal” on page 280
.
Interaction Between IPSec and PPP
PPP defines the Compression Control Protocol (CCP) and the Encryption Control Protocol
(ECP) modes. These modes are currently not supported in the E Series router. There is
no interaction related to encryption directives between IPSec and PPP.
279
Copyright © 2010, Juniper Networks, Inc.
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...