ZyXEL SBG3300-NB00 User Guide - Page 305

Setup, IP Address Pool, L2TP VPN, Encryption, Authentication, Default_L2TPVPN

Page 305 highlights

Chapter 22 L2TP VPN 4 An L2TP client is disconnected unexpectedly. Tip: An L2TP connection will be dropped when one of the followings occurs on the Device: (1) Client has no activity for a period of time. (2) Client loses connectivity to the Device for a period of time. (3) Any IPSec VPN configuration change is applied on the Device. (4) Either Default_L2TPVPN IPSec configuration or L2TP VPN is disabled on the Device. (5) When any one of these configuration changes is applied on the Device: WAN Interface used for L2TP VPN, IP Address Pool, Access Group. (6) The Device WAN interface on which the L2TP connection established is disconnected. 5 An L2TP client is connected successfully but cannot access the local host or server behind the Device. Tip: This may be caused by one of the followings: (1) The local host or server is disconnected. (2) The Access Group is not configured correctly. From the Device's GUI, go to the VPN > L2TP VPN > Setup screen to check. Note that all local hosts are by default accessible unless Access Group is configured. (3) IP Address Pool for L2TP VPN is conflicting with any WAN, LAN, DMZ, WLAN, or PPTP VPN subnet configured on the Device. Note that IP Address Pool for L2TP VPN has 24-bit netmask and should not conflict with any others listed above even if they are not in use. 6 An L2TP client is connected successfully but cannot browse Internet. Tip: From the Device's GUI, click VPN > L2TP VPN > Setup. Check if DNS Server is configured. A client cannot browse Internet without DNS resolved. Note that when a new DNS Server is configured, the client must disconnect then reconnect in order for the new DNS Server to take effect. 7 The L2TP client can no longer connect to SBG3300 after the Encryption or Authentication for the Default_L2TPVPN IPSec VPN rule is changed. Tip: A user usually do not need change the default Encryption or Authentication algorithms in the Default_L2TPVPN IPSec VPN rule. The default Encryption and Authentication algorithms should support the built-in L2TP/IPSec client software in the popular operating systems (Windows (XP, Vista, 7), Android, and iOS). Refer to Table 91 on page 286 for the default setting of the Default_L2TPVPN IPSec VPN rule. As a reference, Table 103 on page 306 lists the IPSec proposals provided by a built-in L2TP client in the popular operating systems during IPSec phase 1 negotiation. The first proposal that can be supported by the phase 1 setting in the Default_L2TPVPN IPSec VPN rule will be accepted by the SBG3300-N Series User's Guide 305

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442

Chapter 22 L2TP VPN
SBG3300-N Series User’s Guide
305
4
An L2TP client is disconnected unexpectedly.
Tip:
An L2TP connection will be dropped when one of the followings occurs on the Device:
(1) Client has no activity for a period of time.
(2) Client loses connectivity to the Device for a period of time.
(3) Any IPSec VPN configuration change is applied on the Device.
(4) Either Default_L2TPVPN IPSec configuration or L2TP VPN is disabled on the Device.
(5) When any one of these configuration changes is applied on the Device: WAN Interface used for
L2TP VPN, IP Address Pool, Access Group.
(6) The Device WAN interface on which the L2TP connection established is disconnected.
5
An L2TP client is connected successfully but cannot access the local host or server behind the
Device.
Tip:
This may be caused by one of the followings:
(1) The local host or server is disconnected.
(2) The Access Group is not configured correctly. From the Device’s GUI, go to the
VPN
>
L2TP
VPN
>
Setup
screen to check. Note that all local hosts are by default accessible unless Access
Group is configured.
(3)
IP Address Pool
for L2TP VPN is conflicting with any WAN, LAN, DMZ, WLAN, or PPTP VPN
subnet configured on the Device. Note that
IP Address Pool
for L2TP VPN has 24-bit netmask and
should not conflict with any others listed above even if they are not in use.
6
An L2TP client is connected successfully but cannot browse Internet.
Tip:
From the Device’s GUI, click
VPN
>
L2TP VPN
>
Setup
. Check if DNS Server is configured. A
client cannot browse Internet without DNS resolved. Note that when a new DNS Server is
configured, the client must disconnect then reconnect in order for the new DNS Server to take
effect.
7
The L2TP client can no longer connect to SBG3300 after the
Encryption
or
Authentication
for the
Default_L2TPVPN
IPSec VPN rule is changed.
Tip:
A user usually do not need change the default
Encryption
or
Authentication
algorithms in
the
Default_L2TPVPN
IPSec VPN rule. The default
Encryption
and
Authentication
algorithms
should support the built-in L2TP/IPSec client software in the popular operating systems (Windows
(XP, Vista, 7), Android, and iOS).
Refer to
Table 91 on page 286
for the default setting of the
Default_L2TPVPN
IPSec VPN rule.
As a reference,
Table 103 on page 306
lists the IPSec proposals provided by a built-in L2TP client in
the popular operating systems during IPSec phase 1 negotiation. The first proposal that can be
supported by the phase 1 setting in the
Default_L2TPVPN
IPSec VPN rule will be accepted by the