MH-5001 User Manual
Chapter 17
Remote Access VPN – L2TP
137
Configuring A L2TP Dial-Up Connection
1. Configure a L2TP dial-up connection
2. Go to
Start
>
Control Panel > Network and Internet
Connections > Make new connection
.
3. Select
Create a connection to the network of your
workplace
and select
Next
.
4. Select
Virtual Private Network Connection
and select
Next
.
5. Give a
Name
the connection and select
Next
.
6. If the
Public Network
dialog box appears, choose the
Don’t dial
up initial connection
and select
Next
.
7. In the
VPN Server Selection
dialog, enter the
public IP
or
hostname
of the MH-5001 to connect to and select
Next
.
8. Set
Connection Availability
to
Only for myself
and select
Next
.
9. Select
Finish
.
Customize the VPN Connection
1. Right-click the icon that you have created.
2. Select
Properties
>
Security > Advanced > Settings.
3. Select
No Encryption
from the
Data Encryption
and click
Apply
.
4. Select the
Properties
>
Networking
tab.
5. Select
L2TP VPN
from the
VPN Type
.
Make sure the following are selected:
TCP/IP
QoS Packet Scheduler
6. Select
Apply
.
Step 2 – Setup Windows XP/2000 L2TP
clients
Note that in the MH-5001 release II version, both
PPTP and L2TP can support MPPE. In other
words, you can choose “
Require data
encryption
” while a client computer running
Windows XP/2000. However, this release II
version will not support MS-CHAP, you have to
check MS-CHAPv2 checkbox if you would like to
require data encryption.
Editing Windows Registry
The default Windows 2000 L2TP traffic policy does not allow L2TP traffic
without IPSec encryption. You can disable default behavior by editing the
Windows 2000 Registry as described in the following steps. Please refer
to the Microsoft documentation for editing the Windows Registry.
1. Use the registry editor (regedit) to locate the following key in the
registry:
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \
Services \ Rasman \ Parameters
2. Add the following registry value to this key:
•
Value
Name:
ProhibitIpSec
•
Data
Type:
REG_DWORD
•
Value:
1
3. Save your changes and restart the computer.
You must add the
ProhibitIpSec
registry value to each Windows
2000-based endpoint computer of an L2TP or IPSec connection to
prevent the automatic filter for L2TP and IPSec traffic from being created.
When the
ProhibitIpSec
registry value is set to
1
, your Windows
2000-based computer does not create the automatic filter that uses CA
authentication. Instead, it checks for a local or Active Directory IPSec
policy.