In part I of this series, we covered the IPSec layer. With IPSec up and running, we can move on to configuring L2TP; routing will be covered in part III.
In the "usual" VPN setup, we'd cut a hole in the existing DHCP pool in the protected network to reserve as addresses to be given to VPN clients. In a /24 subnet, network gear might get addresses up to 30, the DHCP pool could run from 31-150, and other static IPs (hi, printers!) might live at 200-254, with 151-199 open for VPN access.
Unfortunately, my protected network in this scenario is AWS, which I can't actually carve random IPs out of to assign to connecting clients. I have to assign one in a different netblock and hope none of the three (the client, AWS, and my new L2TP-only address pool) conflict.
Luckily, there are three private network spaces defined, and everyone always forgets about the weird one. Let's set up the connection something like this:
Of course I didn't actually use 172.16.0.x myself, that's asking for almost as much trouble as 192.168.0.x. (Also, I guess I could have colored the NAT-to-server link green as well, because that's the same network space in my AWS setup. Too late, we're going!)
