TMS zl Management and Configuration Guide ST.1.1.100430
7-489
Virtual Private Networks
Configure a Windows Vista Client for L2TP over IPsec
TMS zl Module Settings for a Windows Vista Client
Table 7-42 displays the settings that should be established on the TMS zl
Module to support the L2TP over IPsec connection. The table also displays
necessary firewall policies. Also note that VLANs and necessary routes should
already be in place on the TMS zl Module.
Finally, when you authenticate L2TP users to an external RADIUS server,
remember to check your RADIUS server’s set up (see “Set Up a RADIUS Server
to Work with the TMS zl Module” on page 7-174).
Table 7-42. Settings for an L2TP over IPsec Connection on the TMS zl Module
Parameter Valid Settings Configuration Window Matching Setting on the
Windows Vista Client
IKE policy
Policy Type Client-to-Site (Responder) Add IKE Policy—Step 1 of 3
Local Gateway TMS zl Module’s IP address or VLAN that
the remote clients can reach
• Destination address in
the IP filter (step 28 on
page 7-459)
• Internet address for
the VPN connection
(step 71 on page 7-480)
Local ID Type IP Address
Local ID Value Same IP address configured for the Local
Gateway
Remote ID Type • With preshared keys, IP Address
• With digital certificates, the type for
the subject name in the certificate
(typically, Distinguished Name or
Domain Name)
Remote ID Value • With preshared keys, 0.0.0.0
• With digital certificates, a value or
wildcard that matches the certificate
subject name