TMS zl Management and Configuration Guide ST.1.1.100226
7-156
Virtual Private Networks
Configure an L2TP over IPsec VPN
Caution For this policy, you will specify a local TMS zl Module IP address. Be very
careful to specify UDP for the protocol and 1701 for the local and remote ports.
Otherwise, you might select management traffic for the VPN and lock yourself
out of the Web browser interface. If you do lock yourself out, reboot the
module, but DO NOT SAVE the configuration.
If your traffic selector will include traffic that is also selected for NAT, you
must create a NAT exclusion policy. See “Exclusion NAT Policies” in
Chapter 5: “Network Address Translation.”
Refer to Figure 7-132 for help configuring the next setting.
Figure 7-132. Example L2TP over IPsec VPN
8. For Traffic Selector, configure these settings:
a. For Protocol, select UDP.
Note Do not select (115) L2TP for Protocol. You must select UDP and then specify
the L2TP port (1701) for the local and remote ports. L2TP needs to operate
at Layer 4/5 in this case instead of at Layer 3.