Use the WatchGuard L2TP Setup Wizard

The WatchGuard L2TP Setup Wizard helps you activate and configure Mobile VPN with L2TP on the Firebox. The setup wizard is available only when Mobile VPN with L2TP is not activated. The wizard prompts you to configure these settings:

  • Authentication server
  • Users and groups
  • Virtual IP address pool
  • Authentication method

Settings not included in the wizard are set to their default values. After you complete the wizard, you can edit the Mobile VPN with L2TP configuration to change settings you specified in the wizard and other settings.

Before You Begin

You must configure an authentication server for L2TP user authentication before you enable Mobile VPN with L2TP. Make sure that any users and groups you want to use are added to the authentication server. When you configure Mobile VPN with L2TP, you select an authentication server and specify users and groups.

Mobile VPN with L2TP supports two authentication methods: Local authentication on the Firebox (Firebox-DB) and RADIUS. For more information about supported user authentication methods for L2TP, see About Mobile VPN with L2TP User Authentication

You cannot configure Mobile VPN with L2TP if the device configuration already has a branch office VPN gateway that uses main mode and has a remote gateway with a dynamic IP address.

Default Settings

IPSec

When you activate Mobile VPN with L2TP, IPSec is enabled by default with these IPSec settings:

Phase 1 transforms

  • SHA-1, AES(256), and Diffie-Hellman Group 2
  • SHA-1, AES(256), and Diffie-Hellman Group 20
  • SHA2-256, AES(256), and Diffie-Hellman Group 14

The SA life is 8 hours for all transforms.

Phase 2 proposals

  • ESP-AES-SHA1
  • ESP-AES128-SHA1
  • ESP-AES256-SHA256

PFS is disabled by default.

IP Address Pool

By default, the Mobile VPN with L2TP address pool is 192.168.115.0/24.

We recommend that you do not use the private network ranges 192.168.0.0/24 or 192.168.1.0/24 on your corporate or guest networks. These ranges are commonly used on home networks. If a mobile VPN user has a home network range that overlaps with your corporate network range, traffic from the user does not go through the VPN tunnel. To resolve this issue, we recommend that you Migrate to a New Local Network Range.

For more information about virtual IP address pools, see Virtual IP Addresses and Mobile VPNs.

Other Settings

After you complete the wizard, you can configure additional Mobile VPN with L2TP settings that do not appear in the wizard. For information about other settings, see Edit the Mobile VPN with L2TP Configuration.

Use the L2TP Setup Wizard

The steps to start the wizard changed in Fireware v12.3. To start the wizard in Fireware Web UI v12.2.1 or lower, select VPN > Mobile VPN with L2TP and click Run Wizard. To start the wizard in Policy Manager v12.2.1 or lower, select VPN > Mobile VPN > L2TP > Activate.

To configure other settings, edit the Mobile VPN with L2TP configuration.

When you enable Mobile VPN with L2TP, two policies are automatically added to allow L2TP traffic. For more information, see About L2TP Policies.

See Also

Mobile VPN with L2TP

Edit the Mobile VPN with L2TP Configuration

Troubleshoot Mobile VPN with L2TP