Title: L2TP-over-ISPEC For roaming user
1L2TP-over-ISPECFor roaming user
5.5.5.60
DFL-1600
CompanyNetwork
L2TP-over-IPSEC Tunnel
VPN-Gateway1.1.1.1
Road WarriorWindows XP SP2
192.168.123.0/24
2L2TP-over-ISPECFor roaming user
3L2TP-over-ISPECFor roaming user----DFL-1600-setti
ngs-1/7
Create the IP pools, L2tp-servers IP address and
change the IP of wan1 and lan1, subnet mask of
lan1 and wan1, under the Address Book
Under Authentication Objects, create a pre-share
key for the usage of IPSEC tunnel
1
2
4L2TP-over-ISPECFor roaming user----DFL-1600-setti
ngs-2/7
3
Under the Interfaces, create the IPSEC interface
for roaming users.
1. Why I select the Local Network to wan1_ip?
Because we shall let the remote roaming users
knowing the firewall is a final destination.Or
you can set this value to all-nets, let the DFL
unit auto search suitable policy.
2. Due to we dont know the roaming user address
,we also let DFL unit auto search suitable
policy.
5L2TP-over-ISPECFor roaming user----DFL-1600-setti
ngs-3/7
Under the authentication, select the pre-shared
key ipsec-pre that we created in step 2
4
In this scenario we have no use the Xauth
feature.Under the Routing field, enable the
function of Dynamically Add Route To Remote
Net..
5
6L2TP-over-ISPECFor roaming user----DFL-1600-setti
ngs-4/7
6
Under IKE Settings IKEMode Main (Mainmode)
DHGroup 2 PFS None SetupSAPer Host (Per
host) DeadPeerDetection Yes NATTraversal
OnIfNeeded (Only if
needed)? Disable Keep-alive feature Under
Advanced AutoInterfaceNetworkRoute No
7L2TP-over-ISPECFor roaming user----DFL-1600-setti
ngs-5/7
Under Interfaces field, add L2TP servers
interface, below is a step-by-step settings. Note
the field of Outer Interface Filter shall set
to IPSEC interface which is created at STEP 3
7
8L2TP-over-ISPECFor roaming user----DFL-1600-setti
ngs-6/7
Add Local User DatabaseAdd User Authentication
rule
8
9L2TP-over-ISPECFor roaming user----DFL-1600-setti
ngs-7/7
Add Interface Groupes, grouping the interface of
L2TP and LAN1 for easy setup. Create IP Rules
set, allow bi-direction traffic between the
interfaces of L2TP and lan1.
9
10L2TP-over-ISPECFor roaming user----Windows XP
settings-1/3
Checking the status of IPSEC service on Windows
XP to make sure the IPSEC service is enabled.
1
11L2TP-over-ISPECFor roaming user----Windows XP
settings-2/3
Under the Network Connections---gtCreate a new
connection and following the procedure as below
to set it up.
1
12L2TP-over-ISPECFor roaming user----Windows XP
settings-2/3
After the wizard step by step settings, we shall
adjust some advance value for fitting the
settings with DFL-1600
2
13L2TP-over-ISPECFor roaming userConfirmation-1/2
On the Windows platform, we shall try to connect
the DFL-1600 server and checking the connection
status and to see if we can get the IP address
from L2TP server by using the command tool
ipconfig and ping.
1
14(No Transcript)