Re: VPN Client confusion/help



Hi,

> But something tells me that IPSEC is better and more secure so i have
> been trying to get it work with no luck.

IPSEC without L2TP is supported only in Site to Site connections with
ISA server. Client VPN supports only PPTP or L2TP/IPSEC. L2TP/IPSEC
provides mor securiyt as PPTP, but a correct configured VPN with PPTP
and EAP or long an complex passwords provides also enough security for
many business.

> Is PPTP really that insecure or weak? i just wnat a secure vpn server
> that works and i believe ISA 2004 does this well.

ISA works with PPTP an L2TP/IPSEC for client VPN and IPSEC for S2S VPN
only for compatibility reasons.

> Netscreen firewall --- ISA 2004 ext Nic (193.x.x.x) --- ISA 2004
> Internal Nic (10.8.x.x
> I am not sure if i have got the certificates right but when the
> clients try and connect using L2TP it just times out (server did not
> respond)

the ISA Server is the VPN endpoint? Than you have to configure the
netscreen firewall for VPN passthrough. Read the Netscreen KB. Have you
tried to establish a connection from one client behind ISA without the
router to ensure that the Netscreen fiewall has no problem.

Is your client configured with Windows XP and SP2? There are some
changes in the NATT behaviour so you have to enable a reg key at your
client!
http://support.microsoft.com/default.aspx?scid=kb;en-us;885407

regards Jens
www.nt-faq.de


.



Relevant Pages

  • Re: Outgoing VPN Error 619
    ... Outbound VPN problem: ... Q1 - is the test client configured as SecureNET? ... Q2 - what do you find in the ISA logs for your tests? ... I've checked in local network rules and I do have a rule called VPN clients ...
    (microsoft.public.isa.vpn)
  • RE: VPN timeouts
    ... I do not use ISA & was wondering if there is a configurable option on the ... You remote clients VPN connection will timeout while trying to connect SBS ... between remote client and SBS server which caused by lack of network ...
    (microsoft.public.windows.server.sbs)
  • Re: Unable to make VPN connection to ISA 2006 Standard
    ... Router and the isa server this nat enabled, then the pptp tunnel will fail? ... If i initialize an vpn connection with a windows client, ...
    (microsoft.public.isa.vpn)
  • RE: ISA2004 kills VPN outbound
    ... I understand that after you upgraded ISA 2000 to ISA ... 825763 How to configure Internet access in Windows Small Business Server ... Then, establish the VPN connection again, does it work this time? ... FW client and configure the client as a SecureNAT client. ...
    (microsoft.public.windows.server.sbs)
  • Re: Outgoing VPN Error 619
    ... With the outgoing PPTP VPN's I have that allow all rule but they are still ... PPTP clients are configured to use ISA as a hop to the Internet (SecureNET ... Neither a web proxy client nor a Firewall client host ... SecureNAT Clients while still trying to have Web and Firewall Client ...
    (microsoft.public.isa.vpn)