TMS zl Management and Configuration Guide ST.1.1.100430

7-158
Virtual Private Networks
Configure an L2TP over IPsec VPN
Figure 7-132. Example L2TP over IPsec VPN
8. For Traffic Selector, configure these settings:
a. For Protocol, select UDP.
Note Do not select (115) L2TP for Protocol. You must select UDP and then specify
the L2TP port (1701) for the local and remote ports. L2TP needs to operate
at Layer 4/5 in this case instead of at Layer 3.
b. For Local Address, type the IP address configured as the local gateway
in the IKE policy (indicated by 1 in the figure).
c. For Local Port, type 1701.
d. For Remote Address, select Any.
Alternatively, you could specify a specific IP address, range of IP
addresses, or subnet (indicated by 3 in the figure). However, this
complicates the configuration in one of two ways:
By default, Windows L2TP clients send their IP address as their
local address. Because this setting must match the remote setting
exactly, you would need to configure a separate IPsec policy for
each L2TP client. You would also have to know the IP address of
each client.