Re: L2TP/IPSEC VPN - Fehler 791 - Windows 2003 Server - Siemens Gigaset SE515

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Johannes R. (TheRedDevil_at_gmx.de)
Date: 08/29/04

  • Next message: Christian: "Sicherheitscenter - deaktivieren von Antivirus"
    Date: Sun, 29 Aug 2004 02:00:43 +0200
    
    

    Lösung gefunden:

    siehe:

    Von: "TD" <dsmtoday@gmail.com>
    Betreff: Re: L2TP + NAT-T (SOLUTION)
    Datum: Dienstag, 24. August 2004 23:39

    Once you get it figured out for WinXP SP1, it will stop working when
    SP2 gets installed. So here's some advance info to remember for when
    you do that upgrade.

    The fix to this problem is discussed here
    http://zdnet.com.com/2100-1105-5321783.html

    Basically, Microsoft considers L2TP/IPSEC via NAT insecure. So
    they've added a key and made it default to killing the functionality
    of the SP1 NAT-T patch. And they don't give you any place to modify
    this key value. So you have to import it by hand. And you MUST
    reboot after installing this key.

    Here's the regedit patch.
    -------------------------

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec]
    "AssumeUDPEncapsulationContextOnSendRule"=dword:00000002


  • Next message: Christian: "Sicherheitscenter - deaktivieren von Antivirus"

    Relevant Pages

    • Re: L2TP/IPSec VPN: Error 791
      ... Betreff: Re: L2TP + NAT-T ... Once you get it figured out for WinXP SP1, ... of the SP1 NAT-T patch. ... reboot after installing this key. ...
      (microsoft.public.win2000.ras_routing)
    • Re: L2TP + NAT-T (SOLUTION)
      ... Once you get it figured out for WinXP SP1, ... SP2 gets installed. ... of the SP1 NAT-T patch. ... reboot after installing this key. ...
      (microsoft.public.win2000.ras_routing)
    • Re: reinstall patch
      ... You have WinXP SP1 installed, the fixes in which supersede KB328310. ... Your reply also tells me that you're not up-to-date with IE/OE patches, ... alone installing WinXP SP2). ... > hi i get these patch: ...
      (microsoft.public.windowsxp.general)
    • XP SP2 NAT-T Issue
      ... Prior to installing XP SP2, we installed KB 818043 on our XP Desktops to ... handle the NAT-T for IPSEC between our Internal network and our DMZ. ... We installed XP SP2 and the NAT-T no longer works. ...
      (microsoft.public.windowsxp.general)
    • FAST_IPSEC and NAT-T
      ... When installing the ipsec-tools it says if you want NAT-T you need to install this patch, ... Can any one tell me if this patch works with Fast_ipsec or is it just for the other ipsec? ...
      (freebsd-net)