TMS zl Management and Configuration Guide ST.1.0.090213

7-222
Virtual Private Networks
Configure the VPN Client
Configure a Windows Vista Client for L2TP over IPsec
This section includes step-by-step instructions for configuring a Windows
Vista client to establish a L2TP over IPsec connection to the TMS zl Module.
On Windows Vista, you must configure IPsec policies manually.
For the configuration to work, you must also configure L2TP over IPsec
settings on the module as described in “Configuring L2TP over IPsec” on
page 7-96. See “TMS zl Module Settings for an L2TP over IPsec Connection to
a Manually Configured Client” on page 7-218 for a table that shows all neces-
sary settings.
Firewall access policies
User Group None Permit Self <remote endpoints’ zone> UDP 1701
Any Any
Permit <remote endpoints’ zone> Self UDP 1701
Any Any
Permit Self <remote endpoints’ zone> isakmp
Any Any
Permit <remote endpoints’ zone> Self isakmp
Any Any
Add Policy
User Group None
or User Group
<group
configured for
the dial-in user>
Permit External <local zone> Any <virtual dial-
in addresses> <local addresses>
Permit <local zone> External Any <virtual dial-
in addresses> <local addresses>
Add Policy
Parameter Valid Settings Configuration
Window
Matching Setting on the
Windows XP Client
(Manual Method)