Configuring L2TP Settings

This chapter describes how to enable L2TP, configuring basic settings and access control.

  1. Open the Remote Access > L2TP over IPsec > Global tab.

  2. Enable L2TP over IPsec.

    Enable L2TP over IPsec remote access by clicking the Enable button.

    The toggle switch turns amber and the page becomes editable.

Server Settings and IP Address Management

  1. In the Server Settings and IP Address Management section, make the following settings:

    Interface: Select the network interface to use for L2TP access.

    Note – If you use uplink balancing, only the primary interface that is up will be used for L2TP traffic.

    Authentication mode: L2TP over IPsec remote access supports authentication based on Preshared keys or X.509 CA check:

    Assign IP addresses by: The IP addresses can either be assigned from a predefined IP address pool during the dial-up or can be automatically requested from a DHCP server.

  2. Click Apply to save your settings.

    The toggle switch turns green. L2TP over IPsec is active now.

Access Control

L2TP remote access supports Local and RADIUS authentication. For users using other authentication methods remote access will not work. For local users, UTM supports the authentication protocols MS-CHAPv2 and PAP (local authentication). By default, a MS Windows client negotiates MS-CHAPv2.

You can use RADIUS authentication, if you have defined a RADIUS server on the Definitions & Users > Authentication Servers > Servers tab. In conjunction with RADIUS authentication, UTM supports the authentication protocols MS-CHAPv2, MS-CHAP, CHAP, and PAP. The authentication requests are forwarded to the RADIUS server. The L2TP module sends the following string as NAS-ID to the RADIUS server: l2tp. The authentication algorithm gets automatically negotiated between client and server.

Cross Reference – The configuration of the Microsoft IAS RADIUS server and the configuration of RADIUS within WebAdmin is described in the UTM administration guide in chapter Definitions & Users.

  1. In the Access Control section, select an authentication method.

    Authentication via: Select the authentication method.

    Users and groups: When using Local authentication, please also select the users and groups that should be able to use L2TP remote access.

  2. Click Apply to save your settings.

Cross Reference – More detailed information on the configuration of a remote access and detailed explanations of the individual settings can be found in the UTM administration guide in chapter Remote Access.

© 2019 Sophos Limited Sophos UTM 9.600