Hardware firewall blocking L2TP/IPSec VPN



Hi,

I have been running PPTP VPN's at my workplace for a while now but we
have decided to upgrade these to L2TP/IPSec as some clients are going
to be more mobile and using Wi-Fi etc.

We are using ISA 2000 at the office I am trying to VPN into, I have
setup the relevent packet filters for UDP 500, 4500 and 1701 aswell as
forwarding the relevent traffic on my external firewall (D-Link
DFL-700). I have pretty much followed the guides in the ISA Server
2000 VPN Delpoyment kit on isaserver.org.

I have setup an enterprise CA which appears to supply certificates as
it should.

When I try to connect to the ISA Server I get a Error 792 message, my
syslogger shows the messege - No proposal chosen. I have tried this
using both certificates and pre-shared keys.

We currently have a site-site VPN tunnel setup via our hardware
firewalls, this allows me to VPN from the main office to the Remote
office (ISA 2000) Server using the external interface IP
(192.168.2.2), when i try this I can connect using L2TP with
certificates no problem, this leads me to believe that it is a problem
with the configuration of the external firewalls.

Any help would be greatly appreciated as I have been through every
guide and webpage I can find but I cant seem to get to the bottom of
this.

Regards

Ian

.



Relevant Pages

  • Re: Hardware firewall blocking L2TP/IPSec VPN
    ... forwarding the relevent traffic on my external firewall (D-Link ... I have pretty much followed the guides in the ISA Server ... 2000 VPN Delpoyment kit on isaserver.org. ... I have setup an enterprise CA which appears to supply certificates as ...
    (microsoft.public.isa.vpn)
  • Re: ISA VPn Server
    ... not ISA authenticates VPN connections and it can use RADIUS to accomplish this. ... If you wan't to use ISA Server as a VPn Server for an A..D Domain, ... How do you publish the required certificates for a stand alone ISA ...
    (microsoft.public.isa.vpn)
  • Re: Secure VPN access
    ... with it's security option for the client. ... After getting the VPN connection I check the Ip settings and found the ... point to the head ISP's DNS server. ... > Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Desktop from LAN not working
    ... the ISA Server policies that are created by the SBS ... I think your outbound VPN connection is not established properly ... On the Add Network Entities page, expand Networks, select Internal, ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Access
    ... offices to connect to head office and access head office resource. ... Site to Site VPN ... The Site to Site VPN request ISA server, so please ensure whether your SBS ...
    (microsoft.public.windows.server.sbs)

Loading