L2TP

Layer 2 Tunneling Protocol (L2TP), as the name implies, operates on the data link layer of the seven-layer OSI model. It does not provide any encryption or confidentiality. For those, it must rely on whatever encryption protocol is passing through its tunnel. For that reason, it is often used in combination with IPsec, which does provide both encryption and confidentiality. The proposed standard for L2TP can be found in RFC 2661.

Each L2TP connection has a client end and a server end. The client end is called the L2TP Access Concentrator (LAC), and the server end is called the L2TP Network Server (LNS). We configure the LNS end, and this then waits for new connections. The LNS end can also initiate connections. The packets within an L2TP are either control packets or data packets. The exchange of control packets is what initiates an L2TP connection; L2TP provides reliability for the control packets. No reliability is provided for data packets; such reliability can be provided by protocols running inside the L2TP tunnel. Once an L2TP tunnel is established, the network traffic between the two ends is bidirectional. It is also possible to have multiple virtual networks within a single L2TP tunnel, as L2TP will isolate each connection within the tunnel.

The combination of IPsec running within an L2TP tunnel is known as L2TP/IPsec. Establishing such a connection involves several steps. First, an IPsec Security Association is negotiated, typically (but not always) with IKE or IKEv2. Second, ESP communication is established in transport mode. Finally, an L2TP tunnel is established. L2TP uses UDP as its transport layer protocol, and its default port is 1701.

When L2TP is used without any other protocols, it is often called native L2TP. You are unlikely to ever use L2TP in native mode, because of the aforementioned lack of encryption or confidentiality. L2TP is often used in conjunction with IPsec, and it can be combined with other protocols, in order to provide the confidentiality and encryption needed (for example, L2TP/PPP).

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.191.236.174