> Source: [sk87523](https://support.checkpoint.com/results/sk/sk87523)

# sk87523 - How to configure an L2TP connection from a Windows client to a Locally Managed Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk87523 |
| Date Created | 2013-05-05 |
| Last Modified | 2026-04-14 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 1500, 1900, 2000, 1600, 1800, 2500, 910 |

## Solution

Follow the steps below to configure an L2TP connection from a Windows-based client to a locally managed Quantum Spark Appliance.

### **Step 1 - Enable an L2TP connection on the Locally Managed appliance:**

1. In the WebUI, from the left navigation panel, click the **VPN** view.

2. In the **Remote Access** section, click the **Blade Control** page.

3. In the **VPN Remote Access Control** section, select **On**.

4. For **VPN Remote Access users can connect via** , select the checkbox for **Windows VPN Client**.

5. In the **Windows VPN Client** line, click the **L2TP Pre-Shared Key** link, enter the preshared key, and click **OK**.

   **Note** - Copy this preshared key - you must enter it in the L2TP connection settings on the Windows OS client.
6. At the bottom of the page, click **Apply**.

7. See these sections in the Locally Managed Administration Guide (for R81.10.X releases see [sk179615](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk179615), for R80.20.X releases see [sk165734](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165734)):

   * Common Configuration Scenarios \> Configuring VPN \> Configuring Remote Access VPN

   * Appliance Configuration \> Managing VPN

8. In the **Windows VPN Client** line, click the **How to connect** link.

   The popup window L2TP VPN Client Usage opens with the next steps and the information you must enter the L2TP connection settings on the Windows OS client.

### **Step 2 - Configure a new L2TP connection on the Windows OS client:**

Refer to the Microsoft documentation for your Windows OS version.

In L2TP connection settings:

1. Enter the the server IP address and the pre-shared secret as you see in the popup window **L2TP VPN Client Usage** in the appliance WebUI.

2. In the **Data encryption** settings, select **Optional Encryption (connect even if no encryption)**.

3. In the **Authentication** settings, select only **Unencrypted password (PAP)** and clear all other options.

### **Step 3 - Start the L2TP connection on the Windows OS client:**

Refer to the Microsoft documentation for your Windows OS version.

**Important Note:**

Starting from the R81.10.10 Jumbo Hotfix and higher versions, the Remote Access Encryption algorithm for phase 2 was changed from **3DES** to **AES-256** . As a result, selecting the **Data encryption** setting as **Require encryption (disconnect if server declines)** in the Windows OS Client will result in L2TP connection failure.

To resolve this issue, the Windows OS client must support **AES-256** as the phase 2 encryption algorithm. Alternatively, modify the phase 2 encryption algorithm used by the appliance to AES-128 using the advanced setting "Remote Access VPN - Encryption algorithm used for phase 2".

### **Related Solutions:**

* [sk98656 - Windows L2TP users cannot connect, Windows shows error 809. L2TP client continuously sends "delete" for Phase 2 keys after Phase 2 completion.](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98656)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
