Re: RRAS and Preshared Key

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/24/04


Date: Sat, 24 Jul 2004 01:11:53 GMT

L2tp will not work over a NAT router due to the way that NAT mangles IP headers and
ipsec thinks that there has been a compromise to the packet. You will have to use
pptp in your situation. --- Steve

"Ben" <Ben@discussions.microsoft.com> wrote in message
news:D9B2B06B-9E4A-4538-BF93-27A14B27FADE@microsoft.com...
> Can anyone give me a hand on this? I set up RRAS in a test environment and I'm
trying to connect to my server on the same LAN. I set up a new IPSEC policy on both
my client and my server to use the same preshared Key. Everytime I attempt to
connect via vpn I only get a pptp connection even when I'm trying to connect by
IPSEC/L2TP? This is a standalone machine (ie not part of a domain). This is a
Windows 2k server with windows 2k pro client. The only way I found to enable a
preshared key on the client and server was by setting up a IPSEC policy. Is there
anything I am forgetting or doing incorrectly. I attempted to use CA in earlier
temps but still go the same error. 792. I started over and tried to use a preshared
key and do it this way with no avail. Same error message. This is pretty simple
labe set up. Using a Linksy router with 8 port switch. I'm starting to think it
might be the router/firewall not allowing IPSEC/L2TP authentication. Any
Suggestions. Thanks.



Relevant Pages

  • Re: =?UTF-8?Q?Risikoeinsch=C3=A4tzung?=
    ... liche Lizenz fuer den Router, ... Sicherheit wie IPSEC, und laesst sich (da nur ein TCP oder UDP Port, ... korenen Server durchleiten ... ...
    (de.comp.security.misc)
  • Re: VPN NOVICE
    ... Want to allow VPN connection to that server. ... >> Purchased Linksys VP41 router, ... >> not using IPSEC, so I have none. ... I asked why if I was wanting to use PPTP ...
    (microsoft.public.windows.server.sbs)
  • Re: Please help: How to connect using a specific IP address
    ... I need to connect to an application using a specific IP, i.e. the server I will connect to will see that specific IP address ... both applications will connect to one server across the Internet ... the router to the my server where my applications are running ... Are you talking about some simple NAT router that's suppose to be able to handle two external or public facing WAN/IP? ...
    (microsoft.public.dotnet.general)
  • Re: new Poll: IPSEC support in HP TCPIP
    ... which is in marked contrast to the lack of interest in the IPSEC EAK. ... If you have a VMS server and a router connecting to the internet. ...
    (comp.os.vms)
  • Re: new Poll: IPSEC support in HP TCPIP
    ... which is in marked contrast to the lack of interest in the IPSEC EAK. ... If you have a VMS server and a router connecting to the internet. ... Why did people not show more interest in the EAK? ...
    (comp.os.vms)