ZyWALL User's Guide

ZyWALL USG 100/200 Series User’s Guide
409
CHAPTER 25
L2TP VPN
25.1 Overview
L2TP VPN lets remote users use the L2TP and IPSec client software included with their
computers’ operating systems to securely connect to the network behind the ZyWALL. The
remote users do not need their own IPSec gateways or VPN client software.
Figure 295 L2TP VPN Overview
25.1.1 What You Can Do in the L2TP VPN Screens
Use the L2TP VPN screen (see Section 25.2 on page 411) to configure the ZyWALL’s
L2TP VPN settings.
Use the L2TP VPN screen (see Section 25.3 on page 412) to display and manage the
ZyWALL’s connected L2TP VPN sessions.
25.1.2 What You Need to Know About L2TP VPN
The Layer 2 Tunneling Protocol (L2TP) works at layer 2 (the data link layer) to tunnel
network traffic between two peers over another network (like the Internet). In L2TP VPN, an
IPSec VPN tunnel is established first and then an L2TP tunnel is built inside it. See Chapter 20
on page 351 for information on IPSec VPN.
" At the time of writing the L2TP remote user must have a public IP address in
order for L2TP VPN to work (the remote user cannot be behind a NAT router
or a firewall).
L2TP Tunnel
IPSec VPN Tunnel