SETUP/STEP BY STEP PROCEDURE:
Step 1: Set Up the L2TP VPN Tunnel on the ZyWALL/USG
1 In the ZyWALL/USG, go to CONFIGURATION > Quick Setup > VPN
Setup Wizard, use the VPN Settings for L2TP VPN Settings wizard to
create a L2TP VPN rule that can be used with the Window 10 clients.
Click Next.
Quick Setup > VPN Setup Wizard > Welcome
2 Then, configure the Rule Name and set My Address to be
the wan1 interface which is connected to the Internet. Type a secure Pre-
Shared Key (8-32 characters).
Quick Setup > VPN Setup Wizard > Welcome > VPN Settings
3 Assign the L2TP users’ IP address range from 192.168.100.10 to
192.168.100.20 for use in the L2TP VPN tunnel and select Allow L2TP traffic
Through WAN to allow traffic from L2TP clients to go to the Internet.
Click OK.
Quick Setup > VPN Setup Wizard > Welcome > VPN Settings (L2TP VPN
Settings)
4 This screen provides a read-only summary of the VPN tunnel. Click Save.
Quick Setup > VPN Setup Wizard > Welcome > VPN Settings (Summary)
5 Now the rule is configured on the ZyWALL/USG. The rule settings appear
in the VPN > L2TP VPN screen. Click Close to exit the wizard.
Quick Setup > VPN Setup Wizard > Welcome > VPN Settings > Wizard
Completed
6 Go to CONFIGURATION > VPN > VPN Gateway > WIZ_L2TP_VPN >
Authentication > Pre-Shared Key
7 Go to CONFIGURATION > VPN > L2TP VPN > Create new Object >
User to add User Name and Password (4-24 characters). Then, set Allowed
User to the newly created object (L2TP_Remote_Users/zyx168 in this
example).
CONFIGURATION > VPN > L2TP VPN > Create new Object > User
8 If some of the traffic from the L2TP clients needs to go to the Internet,
create a policy route to send traffic from the L2TP tunnels out through a WAN
trunk. Set Incoming to Tunnel and select your L2TP VPN connection. Set
the Source Address to be the L2TP address pool. Set the Next-Hop
Type to Trunk and select the appropriate WAN trunk.
CONFIGURATION > Network > Routing > Policy Route
Set Up the L2TP VPN Tunnel on the Windows 10
To configure L2TP VPN in Windows 10 operating system, go to Start >
Settings > Network & Internet > VPN > Add a VPN Connection and
configure as follows.
VPN Provider set to Windows (built-in).
Configure Connection name for you to identify the VPN configuration.
Set Server name or address to be the ZyWALL/USG’s WAN IP address
(172.124.163.150 in this example).
Select VPN type to Layer 2 Tunneling Protocol with IPsec (L2TP/IPsec).
Enter User name and Password which the same as Allowed User created
in ZyWALL/USG (L2TP_Remote_Users/zyx168 in this example).
Go to Control Panel > Network and Internet > Network Connections and
right click Properties. Continue to Security > Advanced settings and
select Use Certificate for authentication.
Click “Advanced settings” and type the pre-shared key.
Remember to enable the “IKE service” before you begin to dial the tunnel.
Go to control panel and please choose “System and Security”.
Choose “Administrator Tools”
Choose “Component Services”.
Make sure the status of “IKE and AuthIP IPs..” is started.
Go to Network & Internet Settings window, click Connect.
VERIFICATION:
Test the L2TP over IPSec VPN Tunnel
1 Go to ZyWALL/USG CONFIGURATION > VPN > IPSec VPN > VPN
Connection, the Status connect icon is lit when the interface is connected.
CONFIGURATION > VPN > IPSec VPN > VPN Connection