L2TP over IPsec PC: Difference between revisions
no edit summary
PauliusRug (talk | contribs) No edit summary |
|||
Line 48: | Line 48: | ||
[[File:L2tpoveripsecserver1f.png|left|L2tpoveripsecserver1|border|class=tlt-border|1100px]] | [[File:L2tpoveripsecserver1f.png|left|L2tpoveripsecserver1|border|class=tlt-border|1100px]] | ||
[[File:L2tpoveripsecserver2f.png|left|L2tpoveripsecserver2|border|class=tlt-border|1100px]] | [[File:L2tpoveripsecserver2f.png|left|L2tpoveripsecserver2|border|class=tlt-border|1100px]] | ||
[[File:Custom options configuration v1.png|center|L2tpoveripsecserverCustom|border|class=tlt-border]] | |||
[[File:IKE Phase1 configuration v1.png|center|L2tpoveripsecserverIKE|border|class=tlt-border]] | |||
*'''Remote VPN endpoint''' - IP address or hostname of the remote IPsec instance. '''Leave empty''' for the server configuration | *'''Remote VPN endpoint''' - IP address or hostname of the remote IPsec instance. '''Leave empty''' for the server configuration | ||
*'''Enable''' - if checked, enables the IPsec instance | *'''Enable''' - if checked, enables the IPsec instance | ||
Line 54: | Line 58: | ||
*'''Type''' - the type of the connection. '''Transport''' encrypts only the payload and Encapsulating Security Payload (ESP) trailer; so the IP header of the original packet is not encrypted. Transport mode is usually used when another tunneling protocol (such as [[VPN#GRE_Tunnel|GRE]], [[VPN#L2TP|L2TP]]) is used to first encapsulate the IP data packet, then IPsec is used to protect the GRE/L2TP tunnel packets. NAT traversal is not supported with the transport mode. | *'''Type''' - the type of the connection. '''Transport''' encrypts only the payload and Encapsulating Security Payload (ESP) trailer; so the IP header of the original packet is not encrypted. Transport mode is usually used when another tunneling protocol (such as [[VPN#GRE_Tunnel|GRE]], [[VPN#L2TP|L2TP]]) is used to first encapsulate the IP data packet, then IPsec is used to protect the GRE/L2TP tunnel packets. NAT traversal is not supported with the transport mode. | ||
*'''Bind to''' - which interface is going to be bind to the IPsec configuration. The L2TP interface must be selected. | *'''Bind to''' - which interface is going to be bind to the IPsec configuration. The L2TP interface must be selected. | ||
*'''Custom option''' - rekey=0 | |||
*'''Encrytion algorith''' - AES 256 | |||
*'''DH group''' - MODP2048 | |||
===PC Client=== | ===PC Client=== |