L2TP/IPSec VPN tunnel Client -> Server

From: Dennis van Vroonhoven (dontknow)
Date: 03/18/04


Date: Thu, 18 Mar 2004 11:28:33 +0100

Hi,

What are the limitations for L2TP/IPSec?
I have a Firewall (which does no NAT), behind that Firewall I have a Windows
2000 Server SP4 configured for NAT and Routing & Remote Access. I have
configured Routing & Remote Access to accept L2TP and PPTP connections. Both
work when connecting from the inside network to the inside ipadress of the
server, but when connecting to the external ipadress the PPTP works fine but
the L2TP fails. Furthermore I will have to get my managed firewall
configured to pass L2TP/IPSec, the only ports needed are L2TP (UDP 1701) and
IPSec (TCP 500)??

Thanks,
Dennis



Relevant Pages

  • IPSEC with IPNAT conundrum
    ... when connecting *one* subnet at to the subnet at. ... NAT on the firewall. ... I am trying to NAT all the internal subnets at to 10.99.99.1. ...
    (freebsd-isp)
  • Re: [SLE] port 25 only accepts connections from localhost
    ... >Are you connecting via a cable modem that is doing NAT or has a firewall ... Does your ISP allow you to have port 25 open? ...
    (SuSE)
  • Re: home network behind NAT and firewall ?
    ... >> real Firewall appliance with more than 20 systems at any given time. ... >> firewall provides for the ability to assign both public (not nat) and ... that would reset the router and allow remote control - it was noted ... >> LAN inside their network and it would never have to reach the ISP's ...
    (comp.security.firewalls)
  • Re: NAT vs. True Firewalls
    ... not just mean packet filter. ... A firewall can be made up of one or more ... components that can block or filter protocol traffic between two networks. ... So a NAT can be as much part of a firewall implementation as the ...
    (comp.security.firewalls)
  • Re: 56k dial up on laptop 802.11G ?
    ... NAT is not FW software. ... > firewall is literally anything that defends your network against ... >>By comparing the way NAT functions between two networks, ... >>And I consider the FW appliance to out class the packet filtering NAT ...
    (alt.internet.wireless)