TMS zl Management and Configuration Guide ST.1.2.100916
7-411
Virtual Private Networks
Configure a Windows XP SP2 Client for L2TP over IPsec
IPsec policy
Action Apply Add IPsec Policy—
Step 1 of 4
Position Any position
Protocol UDP
Local Address TMS zl Module’s public IP address
Matches the IP address set in 12 on page 7-401
Local Port 1701
Remote Address Any
Remote Port Any (empty)
Proposal IPsec proposal that you created for the L2TP
connection
IKEv1 Policy IKE policy that you created for the L2TP connection Add IPsec Policy—
Step 2 of 4
Enable PFS
(Perfect Forward
Secrecy) for keys
Check box is cleared
SA Lifetime in
Seconds
28800
SA Lifetime in
Kilobytes
0
Enable IP
Address Pool for
IRAS (Mode
Config)
Check box is cleared Add IPsec Policy—
Step 3 of 4
Advanced
Settings
(Optional)
Default settings Add IPsec Policy—
Step 4 of 4
L2TP User account (one user for each client if used)
User Matches the username submitted by the remote
client
Add L2TP User—Step
1 of 2
User name configured in
step 32 on page 7-408
Password Match the string submitted by the remote client Password configured in
step 33 on page 7-409
User Group The group on the TMS zl Module that has been
configured with access policies for the remote
user
Authentication
Protocol
•Any
• CHAP
•PAP
• MS-CHAP
Protocols selected in
step 28 on page 7-407
Parameter Valid Settings Configuration
Window
Matching Setting on the
Windows XP Client