TMS zl Management and Configuration Guide ST.1.1.100226
7-448
Virtual Private Networks
Configure a Windows Vista Client for L2TP over IPsec
Configure a Windows Vista Client for
L2TP over IPsec
This section includes step-by-step instructions for configuring a Windows
Vista client to establish a L2TP over IPsec connection to the TMS zl Module.
On Windows Vista, you must configure IPsec policies manually.
For the configuration to work, you must also configure L2TP over IPsec
settings on the module as described in “Configure an L2TP over IPsec VPN”
on page 7-142. See “TMS zl Module Settings for a Windows Vista Client” on
page 7-488 for a table that shows all necessary settings.
Firewall access policies
User Group None • Permit Self <remote endpoints’ zone> UDP 1701
Any Any
• Permit <remote endpoints’ zone> Self UDP 1701
Any Any
• Permit Self <remote endpoints’ zone> isakmp
Any Any
• Permit <remote endpoints’ zone> Self isakmp
Any Any
Add Policy
User Group None
or User Group
<group
configured for
the dial-in user>
• Permit External <local zone> Any <virtual dial-
in addresses> <local addresses>
• Permit <local zone> External Any <virtual dial-
in addresses> <local addresses>
Add Policy
Parameter Valid Settings Configuration
Window
Matching Setting on the
Windows XP Client
(Manual Method)