Creating L2Tp Vpns; Adding L2Tp Users; Configuring L2Tp - Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Creating L2TP VPNs

Copyright © 2010, Juniper Networks, Inc.
Creating device-level L2TP VPN is a three stage process:
Adding L2TP Users on page 605
Configuring L2TP on page 605
Adding a VPN Rule on page 606

Adding L2TP Users

For VPNs that use L2TP to provide remote access services, you must add an L2TP User
to the security device. An L2TP User has an account on the security device that guards
the protected resources in the VPN; when the user attempts to connect to a protected
resource, the security device authenticates the user.
To add a L2TP User for a security device, in the security device configuration
L2TP/XAuth/Local User, click the Add icon. Enter a name for the user, then specify:
User—Select a preconfigured Local User object that is configured for L2TP.
Remote Setting—Select a preconfigured Remote Settings object.
IP Pool—Select a preconfigured IP Pool object.
Static IP—Enter the static IP address of the Local User.

Configuring L2TP

To connect to an L2TP VPN tunnel, the L2TP RAS user uses the IP address and WINS/DNS
information assigned by the user's ISP. However, when the L2TP RAS user sends VPN
traffic through the tunnel, the security device assigns a new IP address and WINS/DNS
information that enables the traffic to reach the destination network.
Enter a name for the L2TP VPN, then specify the following information:
Host Name—Enter the name of the L2TP host.
Outgoing Interface—The outgoing interface is the interface on the security device that
sends and receives VPN traffic. Typically, the outgoing interface is in the untrust zone.
Keep Alive—The number of seconds a VPN member waits between sending hello
packets to an L2TP RAS user.
Peer IP—Enter the IP address of the L2TP peer.
Secret—Enter the shared secret that authenticates communication in the L2TP tunnel.
Remote Settings—Select the preconfigured remote settings object that represents
the DNS and WINS servers assigned to L2TP RAS users after they have connected to
the tunnel.
IP Pool Name—Select the preconfigured IP pool object that represents the available
IP addresses that can be assigned to L2TP RAS users after they have connected to
the tunnel.
Auth Server
Chapter 12: Configuring VPNs
605

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents