How To Configure L2TP VPN Connection for MAC OS X client How To Configure L2TP VPN Connection for MAC OS X client Applicable Version: 10.00 onwards Overview Layer 2 Tunnelling Protocol (L2TP) can be used to create VPN tunnel over public networks such as the Internet. L2TP uses PPP over UDP (port 1701) to tunnel the data. This protocol is based on the client/server model. The function is divided between the L2TP Network Server (LNS) and the L2TP Access Concentrator (LAC). The LNS typically runs on a network gateway such as a router and firewall, while the LAC can be a dial-up Network Access Server (NAS) or a PC with a bundled L2TP client such as Windows or MAC. Cyberoam acts as the LNS to provide an L2TP connection for the MAC OS X client as the LAC. Scenario Configure L2TP VPN Connection for MAC OS X client in Cyberoam. WAN IP: 10.0.0.1 LAN IP: 172.16.16.1 MAC OS X: L2TP VPN Client Configuration The configuration is divided in two (2) sections: 1. Cyberoam Configuration 2. MAC OS X Configuration 1. Cyberoam Configuration You must be logged on to the Web Admin Console as an administrator with Read-Write permission for relevant feature(s). Step 1: Configure L2TP Configuration Go to VPN > L2TP > Configuration and check Enable L2TP and specify the parameters as shown in the table.
Parameter Value Description General Settings Assign IP from Client Information Primary DNS Server 4.2.2.2 Primary DNS Server 8.8.8.8 192.168.1.1-192.168.1.100 Specify the IP address range which will be assigned to the L2TP clients Select the pre-configured Primary DNS server IP address from the list. Select Other to specify another DNS IP address. Select the pre-configured Secondary DNS server IP address from the list. Select Other to specify another DNS IP address. Click Apply to save the settings. Add L2TP Member client Click Add Member(s) to add user/user groups as L2TP member. You can also select multiple users or user groups who are to be allowed access through L2TP Connection. In this demonstration, we select the user john.smith to whom L2TP connection is to be allowed. Step 2: Create L2TP Connection Go to VPN > L2TP > Connection and click Add to add the L2TP connection. Specify the parameters as shown in the table.
Parameter Value Description Name MAC_L2TP_Connection Specify a name for the L2TP Client Policy Default L2TP Select Default L2TP from the list of policies Action on VPN Restart Respond Only Select Respond Only as the action to be taken in case the VPN service or the appliance restarts. Available Options: Respond Only - Keeps connection disabled till the user responds Disabled Keeps connection disabled till the user activates. Authentication Details Authentication Type Preshared Key Select Preshared Key as the authentication type. Available Options: Preshared Key Digital Certificate Preshared Key 12345 Specify the preshared key to be used Confirm Preshared Key 12345 Confirm the preshared key Local Network Details Local WAN Port PortB - 203.88.140.124 Select the local WAN port Remote Network Details Remote Host * Specify IP address of remote host. Specify * for any IP address. Allow NAT Traversal Enabled Check Enable to enable NAT Remote LAN Network Any IP Host Select the IP address or range of remote device. Select Any in case all IP addresses are to be allowed Quick Mode Selectors Local Port 1701 Specify the Local Port number (1 to 65535) to be used by the remote device Remote Port * Enter * as the value for Remote Port. The reason is that Apple devices try to connect from a higher range of port.
Click OK to complete the configuration. How To Configure L2TP VPN Connection for MAC OS X client
Step 3: Activate Connection To activate the connection, click in the Active Column. The Status indicator turns green to show that the connection is activated. 2. MAC OS X Configuration Step 1. Go to System > Preferences > Network and click the sign to create a new connection.
Step 2: Select the Interface as VPN and VPN Type as L2TP over IPSec Specify the Service Name as VPN L2TP. Click Create to create the connection. Step 3: Specify the Server Address as 10.0.0.1 (Cyberoam WAN IP Address) and Account Name as john.smith (Cyberoam Username).
Step 4: Click Authentication Settings to specify the password and the shared key. In the Password field, specify the password for the user john.smith. In Shared Secret field, enter 12345 (Preshared Key). Click OK to complete the authentication settings.
Step 5: Click Apply to complete the L2TP VPN configuration. To connect using this connection, click Connect. The above configuration establishes L2TP VPN connection between Cyberoam and MAC OS X. Document Version: 1.0 17 April, 2014