Built-in VPN client – Windows 7 to Vigor Router – L2TP over IPsec
This document introduces how to create a Host to LAN L2TP over IPSec VPN via the Windows 7 Built-In VPN Client to a Vigor Router. There will be two parts of setting: on a Vigor router, which we use Vigor2920 in this note, and on the computer.
VPN configuration on Vigor2920
VPN configuration on Vigor2920
- Create a Remote Dial-In User profile in VPN and Remote Access >> Remote Dial-In User.
- Enable this account.
- Type the Username and Password.
- Select L2TP with IPsec Policy as Must.
- Type the Pre-Shared Key in VPN and Remote Access >> IPsec General Setup.
VPN Configuration on PC (Windows 7 Built-In VPN Client)
- Set a new connection or network in Control Panel >> Network and Sharing Center.
- Select Connect to a workplace, and click Next.
- Select create a new connection, and click Next.
- Select Use my Internet Connection.
- Type the WAN IP address of the VPN server, which is Vigor2920, and tick the Don't connect nowoption, and click Next.
- Type the Username and Password for L2TP VPN connection, and click Create.
- Please don't click Connect Now, and click Close instead.
- Click Change adapter settings in Control Panel >> Network Sharing Center.
- Right click L2TP over IPSec Connection we created, and then select Properties.
- Select VPN Type as L2TP / IPSec in the Security Tab, and then click Advanced Settings.
- Select Use pre-shared key for authentication, type the Key, and then click OK. The Key should be the same as the Pre-Shared Key setting on Vigor2920.
- Right click L2TP over IPSec Connection, and select Connect.
- Type the Username and Password, and click Connect. The Username and Password should be same as the ones on Vigor2920 VPN Remote Dial In User Profile.
- L2TP over IPSec connection is now established.
Note :
If the L2TP over IPSec tunnel from Windows 7 to Vigor router could not be established successfully, please check the settings below :
- In Control Panel >> Administartive Tools >> Services, please make sure the IPSec Policy Agent service is started.
- In Control Pane l>> Administrative Tools >> Services, please make sure IKE and AuthIP IPSec Keying Modules are started.
- Please check if the ProhibitIpSec value is 0 on Windows registry >> HEKY_LOCAL_MACHINE >> SYSTEM >> CurrentControlSet >> services >> RasMan >> Parameters >> ProhibitIpSec. If it is not, please change the value to 0, and restart Windows 7 to try again. The steps are :a. Open regedit.b. Go to HEKY_LOCAL_MACHINE >> SYSTEM >> CurrentControlSet >> services >> RasMan >> Parameters >> ProhibitIpSec.c. If the ProhibitIpSec value is not 0, right click ProhibitIpSec, and select Modify.d. Type Value as 0, and click OK.e. Reboot the system.