Configuring A FortiGate Unit As An L2TP IPsec Server
Configuring A FortiGate Unit As An L2TP IPsec Server
Configuring A FortiGate Unit As An L2TP IPsec Server
server
The FortiGate implementation of L2TP enables a remote dialup client to establish
an L2TP/IPsec tunnel with the FortiGate unit directly. Creating an L2TP/IPsec tunnel
allows remote users to connect to a private computer network in order to securely
access their resources. For the tunnel to work you must configure a remote client to
connect using an L2TP/IPsec VPN connection. This recipe is designed to work with
a remote Windows 7 L2TP client.
The FortiGate unit must be operating in NAT/Route mode and have a static public IP address.
L2TP/IPsec
Port 1
Internet
L2TP/IPsec
Remote Windows 7
L2TP Client
Internal Network
378
379
380
381
Configuring a remote
Windows 7 L2TP client
To connect to the FortiGate using L2TP, the
remote client must be configured for L2TP/
IPsec. The following configuration was tested
on a PC running Windows 7.
On the Windows PC, create a new VPN
connection.
Right-click on the new connection and select
Properties, then modify the connection with
the settings shown.
382
Results
On the remote users PC, connect to the
Internet using the L2TP/IPsec connection
you created.
Enter the L2TP users credentials and click
Connect.
384