190
13.5 L2TP IPSec VPN
Configure L2TP IPSec VPN
Some general information on L2TP IPSec
L2TP is the acronym for "Layer Two Tunneling Protocol". It is used to provide remote
access to a certain network, typically the LAN. Although the L2TP client has no direct
physical connection to the LAN, an unused LAN IP address is assigned to it. For all
other devices in the LAN, the L2TP client seems to be a physical member of the LAN.
Thus there's no need to change the routing configuration of any LAN device.
SX-GATE provides an L2TP server which authenticates any incoming connection with
a username and a password. Besides authentication, the L2TP server will also assign
an IP to the L2TP client and will reconfigure the network interface so that data packets
for the L2TP client are directed to SX-GATE. While running, the L2TP server extracts
the payload received via the L2TP channel and wraps L2TP around data packets sent
from the LAN to the client.
For privacy, the L2TP connection is protected by an IPSec VPN tunnel. Just like
the L2TP connection, the VPN tunnel is established between SX-GATE and the
L2TP IPSec client. Besides the possibility of using the stronger certificate based
authentication, VPN will encrypt every L2TP packet and ensure the authenticity of all
data packets.
Recapitulating, when an L2TP client communicates with a device inside the LAN,
between the client and SX-GATE the payload is embedded in L2TP which in turn is
embedded in IPSec packets. Any routers in-between will only "see" the IPSec VPN.
Notes regarding this wizard
VPN connections can be configured in various different ways. Not all of them can be
covered by this wizard. This wizard configures a typical L2TP IPSec connection. In
individual cases it will be necessary to make some modifications in other configuration
menus of SX-GATE.
Please read the information provided on the different screens
carefully. Things you have to do outside this wizard will be stated
there.
This wizard will always change the VPN connection named "L2TP" within interface
"ipsec0". If necessary these will be created. When creating interface "ipsec0", it will be
set on top of the current Internet interface as determined by the default route.
Certificate based authentication is preferred, using certificates of a certain trusted
Certificate Authority (CA). If the latter hasn't been determined yet, SX-GATE's builtin
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...