Minimum requirements for IPSec over L2TP - PIX.



We're buying a service from a provider and they said we need to have a device that can manage IPsec over L2TP (not the opposite). PIX should not be able to manage that kind of encapsulation (I'm investigating on it, it's a PIX515 with finesse 7.0.2) and I'm looking for the cheapest solution to build the tunnel.

They say the minimum requirements are 12.4, 128 MB RAM, 32 MB Flash and encr./decry. module and they suggest at least a 1812-K9 router.

Cisco published one of the first documents about the topic in November 2000.
So I think that even a rather old hardware (OK not all old devices) can manage that kind of tunnel. Do you have any idea if I can use hardware like 1720 series or 870 series or a 3640 router?

Moreover is it possible to split the de-encapsulation process by two and let the PIX decrypt the IPsec and forward the L2TP packets to another device that will de-encapsulate them?
They say that would be better to have the same device acting both the decryption/de-encapsulation.

TIA for your suggestions, opinions.

Alex.
.



Relevant Pages

  • Re: Minimum requirements for IPSec over L2TP - PIX.
    ... and let the PIX decrypt the IPsec and forward the ... Do a search on cisco or google for split tunnel and you should ... Yes the PIX is an end point device for tunnel and user VPN. ... The 1812-k9 supports ipsec as part of its IOS. ...
    (comp.dcom.sys.cisco)
  • Win2K3 L2TP VPN server behind Cisco PIX firewall - Help!
    ... I am trying to setup a Windows 2003 L2TP VPN gateway behind a Cisco PIX ... separate path past our PIX firewall by dual-porting the VPN server across the ... access-list outside_access_in remark permit isakmp from any to any ...
    (microsoft.public.windows.server.networking)
  • RE: IPSec = L2TP?
    ... IPSec is not L2TP, however L2TP can ride *on top* of IPSec. ... Any protocol can traverse IPSec, but it needs to be routed in order to ... different IP network to appear to be on the same network as others - and ...
    (Security-Basics)
  • Re: L2TP over IPsec VPN and nat-t
    ... I had seen these articles and was hopeful that this would solve the problem, ... L2TP over IPSec is not supported with NAT Traversal. ... and that is why you can configure IPSec VPN tunnels ...
    (microsoft.public.security)
  • RE: IPSec vs. IPSec/L2TP
    ... The reason people use L2TP is due the need to provide login mechanism ... logging and the rest of the session would be using IPSec. ... > L2TP/IPSec tunnelling instead of a good old IPSec tunnel. ... Earn your MS in Information Security ONLINE ...
    (Security-Basics)