
Chapter 18 L2TP VPN
ZyWALL (ZLD) CLI Reference Guide
154
18.5 L2TP VPN Example
This example uses the following settings in creating a basic L2TP VPN tunnel. See the Web
Configurator User’s Guide for how to configure L2TP in remote user computers using
Windows XP and Windows 2000.
l2tp-over-ipsec
authentication aaa
authentication profile_name
Specifies how the ZyWALL authenticates a remote user before allowing
access to the L2TP VPN tunnel.
The authentication method has the ZyWALL check a user’s user name and
password against the ZyWALL’s local database, a remote LDAP, RADIUS, a
Active Directory server, or more than one of these.
[no] l2tp-over-ipsec user
user_name
Specifies the user or user group that can use the L2TP VPN tunnel. If you
do not configure this, any user with a valid account and password on the
ZyWALL to log in. The no command removes the user name setting.
[no] l2tp-over-ipsec
keepalive-timer <1..180>
The ZyWALL sends a Hello message after waiting this long without
receiving any traffic from the remote user. The ZyWALL disconnects the
VPN tunnel if the remote user does not respond. The no command returns
the default setting.
[no] l2tp-over-ipsec first-
dns-server {ip |
interface_name} {1st-
dns|2nd-dns|3rd-dns}|
{ppp_interface|aux}{1st-
dns|2nd-dns}}
Specifies the first DNS server IP address to assign to the remote users. You
can specify a static IP address, or a DNS server that an interface received
from its DHCP server. The no command removes the setting.
[no] l2tp-over-ipsec second-
dns-server {ip |
interface_name} {1st-
dns|2nd-dns|3rd-dns}|
{ppp_interface|aux}{1st-
dns|2nd-dns}}
Specifies the second DNS server IP address to assign to the remote users.
You can specify a static IP address, or a DNS server that an interface
received from its DHCP server. The no command removes the setting.
[no] l2tp-over-ipsec first-
wins-server ip
Specifies the first WINS server IP address to assign to the remote users.
The no command removes the setting.
[no] l2tp-over-ipsec second-
wins-server ip
Specifies the second WINS server IP address to assign to the remote users.
The no command removes the setting.
no l2tp-over-ipsec session
tunnel-id <0..65535>
Deletes the specified L2TP VPN tunnel.
show l2tp-over-ipsec Displays the L2TP VPN settings.
show l2tp-over-ipsec session Displays current L2TP VPN sessions.
Table 76 L2TP VPN Commands
COMMAND DESCRIPTION
Kommentare zu diesen Handbüchern