> Source: [sk106864](https://support.checkpoint.com/results/sk/sk106864)

# sk106864 - Configure L2TP connection from Mac OS client to Locally Managed 600 / 1100 / 1200R appliance

| Property | Value |
|----------|-------|
| Solution ID | sk106864 |
| Date Created | 2015-07-20 |
| Last Modified | 2017-12-27 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |

## Solution

Enable L2TP connection on the Locally Managed 600 / 1100 / 1200R appliance to allow incoming dial up connection:

1. In WebUI, go to 'VPN' tab.

2. In the left pane, click on 'Blade Control'.

3. In the 'VPN Remote Access Control' section, select 'On'.

4. In the 'VPN Remote Access users can connect via' section, select 'L2TP VPN client'.

5. Click the 'L2TP Pre-Shared Key' link - enter the preshared key - click "OK".  

   **Note:** Copy this preshared key - you will need to enter this key in the L2TP dialer settings on Windows OS client.
6. Click on "Apply" button.

For more details, refer to:

* [600 Appliance Administration Guide](http://supportcontent.checkpoint.com/documentation_download?ID=24000):

  * Chapter 4 'Common Configuration Scenarios' - Configuring VPN - Configuring Remote Access VPN
  * Chapter 5 'Appliance Configuration' - Managing VPN

  <br />

  <br />

* [1100 Appliance Locally Managed Administration Guide](http://supportcontent.checkpoint.com/documentation_download?ID=25040):

  * Chapter 3 'Common Configuration Scenarios' - Configuring VPN - Configuring Remote Access VPN
  * Chapter 4 'Appliance Configuration' - Managing VPN

Here is an example of how to connect to a VPN Gate Public VPN Relay Server by using an L2TP/IPsec VPN Client that is built-in on Mac OS X.

These screenshots are in the English version of Mac OS X. If you use another language, you can still configure it easily by referring to the following instructions.

1. Initial configurations (only once - the first time)
------------------------------------------------------

Click the network icon on the top-right side of the Mac screen. Click "Open Network Preferences..." in the menu.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk106864/011507160111.jpg)

Click the "+" button on the network configuration screen.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk106864/021507160111.jpg)

Select "VPN" as "Interface" , "L2TP over IPsec" as "VPN Type" and click the "Create" button.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk106864/031507160113.jpg)

A new L2TP VPN configuration will be created, and the configuration screen will appear.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk106864/041507160114.jpg)

On this screen, you have to specify either hostname or IP address of the destination (IP address of the Check Point 600/1100/1200R device).

After you specify the "Server Address"(IP address of the Check Point 600/1100/1200R device) , input the user-name in the "Account Name" field, next to the "Server Address" field.

Next, click the "Authentication Settings..." button.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk106864/051507160116.jpg)

The authentication screen will appear.

Input your password in the "Password" field.

Specify the pre-shared key, also in the "Shared Secret" field.

After you input them, click the "OK" button.

After return to the previous screen, check the "Show VPN status in menu bar" and click the "Advanced..." button.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk106864/061507160119.jpg)

The advanced settings will appear.

Check the "Send all traffic over VPN connection"( if needed) and click the "OK" button.

On the VPN connection settings screen, click the "Connect" button to start the VPN connection.

**Tips: (Thanks to Peter Gibbs)**

* In the Network Preferences screen, click on wheel at the bottom of "LHS window/Set Service Order" and ensure that L2TP VPN is located at the top of the list. (Otherwise the connection is likely to fail, either consistently or intermittently.)
* To connect to a server, in "Finder" top toolbar, click on "Go/Connect to Server". Enter the server's IP address provided by your IT administrator and press "Return". Once the log-on window comes up, log onto the server as a user in the usual way.

2. Start a VPN connection
-------------------------

You can start a new VPN connection by clicking the "Connect" button at any time. You can also initiate a VPN connection by clicking the VPN icon on the menu bar.

After the VPN connection is established, the VPN connection setting screen will be shown as below. The "Status" will be "Connected" . Your private IP address on the VPN, and connect duration time will be displayed on the screen.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk106864/071507160123.jpg)

3. Enjoy VPN communication
--------------------------

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
