Chapter 30 L2TP VPN
ZyWALL / USG (ZLD) CLI Reference Guide
206
30.5 L2TP VPN Example
This example uses the following settings in creating a basic L2TP VPN tunnel. See the Web
Configurator User’s Guide for how to configure L2TP in remote user computers using Windows XP
and Windows 2000.
Figure 23
L2TP VPN Example
• The ZyWALL / USG has a static IP address of 172.23.37.205 for the ge3 interface.
• The remote user has a dynamic public IP address and connects through the Internet.
certificate
cert_name
Select the certificate to use to identify the ZyWALL / USG for L2TP VPN
connections. The certificate is used with the EAP, PEAP, and MSCHAPv2
authentication protocols. The certificate must already be configured.
[no] l2tp-over-ipsec user
user_name
Specifies the user or user group that can use the L2TP VPN tunnel. If you do not
configure this, any user with a valid account and password on the ZyWALL / USG to
log in. The
no
command removes the user name setting.
[no] l2tp-over-ipsec keepalive-
timer <1..180>
The ZyWALL / USG sends a Hello message after waiting this long without receiving
any traffic from the remote user. The ZyWALL / USG disconnects the VPN tunnel if
the remote user does not respond. The
no
command returns the default setting.
[no] l2tp-over-ipsec first-dns-
server {
ip
|
interface_name
}
{1st-dns|2nd-dns|3rd-dns}|
{
ppp_interface
}{1st-dns|2nd-
dns}}
Specifies the first DNS server IP address to assign to the remote users. You can
specify a static IP address, or a DNS server that an interface received from its
DHCP server. The
no
command removes the setting.
[no] l2tp-over-ipsec second-dns-
server {
ip
|
interface_name
}
{1st-dns|2nd-dns|3rd-dns}|
{
ppp_interface
}{1st-dns|2nd-
dns}}
Specifies the second DNS server IP address to assign to the remote users. You can
specify a static IP address, or a DNS server that an interface received from its
DHCP server. The
no
command removes the setting.
[no] l2tp-over-ipsec first-wins-
server
ip
Specifies the first WINS server IP address to assign to the remote users. The
no
command removes the setting.
[no] l2tp-over-ipsec second-
wins-server
ip
Specifies the second WINS server IP address to assign to the remote users. The
no
command removes the setting.
no l2tp-over-ipsec session
tunnel-id <0..65535>
Deletes the specified L2TP VPN tunnel.
show l2tp-over-ipsec
Displays the L2TP VPN settings.
show l2tp-over-ipsec session
Displays current L2TP VPN sessions.
Table 114
L2TP VPN Commands
COMMAND
DESCRIPTION
LAN_SUBNET: 192.168.1.1/24
172.23.37.205
L2TP_POOL:
192.168.10.10~192.168.10.20
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...