RA VPN using L2TP/IPsec with pre-shared key
The following figure shows establishment of an L2TP/IPsec VPN session.
Supported Platforms
list_alt
The following figure shows establishment of an L2TP/IPsec VPN session.
With this solution, only user authentication is done at the PPP level (with username/password). Data encryption is provided by the IPsec tunnel. Furthermore, in order to perform encryption, IPsec also requires authentication (studies have shown that IPsec encryption-only mode is not secure) at the host level.
When pre-shared key is used with L2TP/IPsec, all remote clients must be configured with the same PSK for IPsec authentication. This presents both a security challenge and an operations challenge, since when the key is changed, all remote clients must be re-configured. An alternative is to use L2TP/IPsec with X.509 certificates, as discussed in the next section.
Get Started An introduction to the Ciena Vyatta NOS
The Vyatta NOS Overview Get to know more about how Vyatta NOS is the best solution
Vyatta NOS Architecture Overview An overview of the Vyatta NOS system architecture
Troubleshooting Guide Identify common issues with your configuration and network setup
© 2022 Ciena Intellectual Property, All rights reserved