LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-29-2013, 05:28 AM   #1
hahacc
Member
 
Registered: Oct 2010
Posts: 93

Rep: Reputation: 1
Question IPSec and L2TP - why combine them


Hi folks,
I have one problem about IPSec and L2TP which confused me:

As IPSec is able to implement VPN, so why bother to combine L2TP and IPSec together?

Thanks in advance.
 
Old 10-29-2013, 08:13 AM   #2
rtmistler
Moderator
 
Registered: Mar 2011
Location: USA
Distribution: MINT Debian, Angstrom, SUSE, Ubuntu, Debian
Posts: 9,882
Blog Entries: 13

Rep: Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930
IPSec is able to work in transport mode and tunnel mode. In tunnel mode it provides a VPN in a similar manner as L2TP.

L2TP solely provides tunneling, and does not provide security.

However, one can operate IPSec transport mode over an L2TP tunnel. If one uses IPSec in tunnel mode, they do not require L2TP.

The reason why there are two modes is that in transport mode, only the payload is encrypted and therefore all routing information is retained. This was foreseen to potentially be important to some network architectures, so they could choose to use the transport mode and then use L2TP to provide VPN for any users which were remote, but retain the routing information; which makes sense if you're going to use IPSec internally within an office. It would encrypt the payloads to make them secure but not alter the frame headers. I'm just not sure it's used a lot like that.
 
1 members found this post helpful.
Old 10-30-2013, 12:34 PM   #3
baldy3105
Member
 
Registered: Jan 2003
Location: Cambridgeshire, UK
Distribution: Mint (Desktop), Debian (Server)
Posts: 891

Rep: Reputation: 184Reputation: 184
IPSec does not support multicast traffic. So to protect this you would use L2TP to encapsulate the Multicast, then IPSec the L2TP payload. As one example.
 
1 members found this post helpful.
Old 10-31-2013, 05:17 AM   #4
hahacc
Member
 
Registered: Oct 2010
Posts: 93

Original Poster
Rep: Reputation: 1
Thumbs up

Quote:
Originally Posted by baldy3105 View Post
IPSec does not support multicast traffic. So to protect this you would use L2TP to encapsulate the Multicast, then IPSec the L2TP payload. As one example.
Thanks, this is really helpful.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
l2tp/ipsec gateway configuration allohakdan Linux - Networking 0 10-04-2013 09:47 PM
OpenSWAN, L2TP/IPSEC on CentOS 5.5 bderry71 Linux - Server 1 10-05-2010 09:33 PM
Allowing IPSec/L2TP in Iptables ajayan Linux - Networking 1 06-05-2010 09:21 AM
IPSEC with L2TP in linux shesha_gp Linux - Server 4 04-29-2010 09:11 AM
IPSec/L2TP mahesh_sonawane Linux - Networking 1 06-04-2007 01:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration