User's Manual Part 1
Chapter 8 Security
BM2022w User’s Guide
138
This screen contains the following fields:
Table 58 L2TP Server
LABEL DESCRIPTION
L2TP Server
Enable Use this field to turn the BM2022w’S L2TP VPN function on or off.
Server Name Enter the server name for the L2TP VPN connection.
Support
Protocol
Version
Select the L2TP Protocol Version 2 or 3. L2TPv2 is a standard method for
tunneling Point-to-Point Protocol (PPP) while L2TPv3 provides improved support
for other types of networks including frame relay and ATM.
Auth Protocol Select the Authentication Protocol allowed for the connection. Options are:
PAP - Password Authentication Protocol (PAP) authentication occurs in clear text
and does not use encryption. It’s probably not a good idea to rely on this for
security.
CHAP - Challenge Handshake Authentication Protocol (CHAP) provides
authentication through a shared secret key and uses a three way handshake.
MSCHAPv1 - Microsoft CHAP v1 (MSCHAPv1) provides authentication through a
shared secret key and uses a three way handshake. It provides improved
usability with Microsoft products.
MSCHAPv2 - Microsoft CHAP v2 (MSCHAPv2) provides encryption through a
shared secret key and uses a three way handshake. It provides additional
security over MSCHAPv1, including two-way authentication.
MPPE
Encryption
If MSCHAPv1 or MSCHAPv2 is selected as an Auth Protocol, use the drop-
down list box to select the type of Microsoft Point-to-Point Encryption (MPPE).
Options are:
MPPE 40 - MPPE with 40 bit session key length
MPPE 128 - MPPE with 128 bit session key length
Auto - Automatically select either MPPE 40 or MPPE 128
Local IP
Address
Enter the local endpoint for the L2TP connection.
Remote Start
IP
Enter the local IP address range the BM2022w assigns to remote users if the
remote client device is set to obtain an IP address automatically.
Restrict Client
IP?
Select Yes to restrict the remote client device local IP address.
Allow Client IP Enter the local IP address range the remote client device is restricted to. If the
client device is configured with a static IP address, it should be in this range.
Idle Timeout Enter the time in minutes to timeout L2TP connections.
DNS Server 1
DNS Server 2
Specify the IP addresses of DNS servers to assign to the remote users.
User Access List
User Name Enter the user name for the remote user.
Server Select the server that the remote user has access to: PPTPD, L2TPD or Both.
Password Enter the password for the remote user.
IP Address Enter the local IP address the BM2022w assigns to the remote user.
Entering 0.0.0.0 indicates the local IP address will be dynamically assigned.
Delete Select an entry and click this to delete it.
Add Click this to create a new entry.
OK Click this to save the changes.