WARNING: This site is intended for online use only; mass-downloading of pages degrades the server and is prohibited.
If you attempt to use tools to mass-download the site, you may be blocked permanently by automated software.
If you want to read this CertiGuide offline, please use one of the links on the left to purchase a convenient PDF copy. Thank you.

Like this CertiGuide? Get it in PDF format!
Click Here!
Use coupon code "certiguide" to save 20%!
(Expires 2004/12/31)

Also available: 300-question Security+ practice test!
Get It Here!

Google
Web CertiGuide






Table Of Contents  CertiGuide to Security+
 9  Chapter 2:  Communication Security (Domain 2.0; 20%)
      9  2.1  Remote Access

Previous Topic/Section
2.1.4  TACACS/XTACACS/TACACS+
Previous Page
Pages in Current Topic/Section
12
3
Next Page
2.1.6  SSH
Next Topic/Section

2.1.5  L2TP/PPTP
(Page 3 of 3)

L2TP



L2TP was intended as a replacement for PPTP by Cisco because they didn't care for some (rather lack of) features in PPTP. L2TP combines the best features from PPTP and Cisco’s L2F protocol, which was designed to facilitate tunneling over a variety of media/lower-level protocols such as frame relay and ATM, in addition to the IP-based tunneling supported by PPTP. L2TP supports PAP, CHAP, MS-CHAP and other authentication protocols.

As opposed to PPTP, whose client access is normally implemented by software running on individual desktops, L2TP clients most commonly connect into their VPN by going through a special hardware device that handles the L2TP tunneling. While Windows 2000 is quite capable of supporting L2TP natively many firms don't want to consume the server resources with L2TP

Additionally, with L2TP, the server side generally chooses the endpoint of the communication, a situation that is known as compulsory tunneling (in contrast to PPTP, where the endpoint is normally left up to the client). This scenario lends itself to the construction of hierarchically routed networks which gradually concentrate VPN traffic over fewer but higher bandwidth lines for more efficient transmission over a long haul151.

IPSec is the preferred encryption mechanism used in conjunction with L2TP, but sometimes 40 or 56-bit DES may be used as well. L2TP and L2F use UDP port 1701 for communication on the source and destination hosts, so if you are passing L2TP through a firewall, you need to ensure that port is open.

L2TP

L2TP was intended as a replacement for PPTP and L2F, combining the best features of both.

L2TP supports PAP, CHAP, MS-CHAP and other authentication protocols.

L2TP and L2F use UDP port 1701.

PPTP, L2F and L2TP are all Layer 2 tunneling protocols.



 __________________

151. “Layer 2 Tunnel Protocol”, Cisco Systems, http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/120newft/120t/120t1/l2tpt.htm

Previous Topic/Section
2.1.4  TACACS/XTACACS/TACACS+
Previous Page
Pages in Current Topic/Section
12
3
Next Page
2.1.6  SSH
Next Topic/Section

If you find CertiGuide.com useful, please consider making a small Paypal donation to help the site, using one of the buttons below. You can also donate a custom amount using the far right button (not less than $1 please, or PayPal gets most/all of your money!) In lieu of a larger donation, you may wish to consider buying an inexpensive PDF equivalent of the CertiGuide to Security+ from StudyExam4Less.com. (Use coupon code "certiguide" by December 31, 2004 to save 20%!) Thanks for your support!
Donate $2
Donate $5
Donate $10
Donate $20
Donate $30
Donate: $



Home - Table Of Contents - Contact Us

CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com
Version 1.0 - Version Date: November 15, 2004

Adapted with permission from a work created by Tcat Houser et al.
CertiGuide.com Version © Copyright 2004 Charles M. Kozierok. All Rights Reserved.
Not responsible for any loss resulting from the use of this site.