Re: IPSec VPN into XP Pro

From: Jeffrey Randow (MVP) (jeffreyr-support_at_remotenetworktechnology.com)
Date: 02/24/05


Date: Wed, 23 Feb 2005 20:41:59 -0600

XP can act as an IPSEC server.. It can't do NAT-T, though.. Thus you
must have static IP's and use the fullblown L2TP, which is much more
difficult to use...

---
Jeffrey Randow (Network MVP)
Remote Networking Technology FAQ -
http://www.remotenetworktechnology.com
My Networking Blog:  http://www.networkblog.net
MS Network Community -
http://www.microsoft.com/windowsserver2003/community/centers/networking/default.mspx
MS Home Networking Community -
http://www.microsoft.com/windowsxp/expertzone/communities/wireless.mspx
On Wed, 23 Feb 2005 16:29:59 -0600, "Sooner Al [MVP]"
<SoonerAl@somewhere.net.invalid> wrote:
>AFAIK, and I certainly could be wrong about this, but XP can't act as an IPSec server...Others can 
>speak to that issue.
>
>You can, however, setup a PPTP VPN tunnel...
>
>http://www.onecomputerguy.com/networking/xp_vpn_server.htm
>http://www.onecomputerguy.com/networking/xp_vpn.htm
>
>In the case of PPTP VPN you need to forward TCP Port 1723 and enable GRE Protocol 47 traffic through 
>any firewall/NAT/router at the server end to the private LAN IP of the PPTP VPN server. The later is 
>sometimes called "PPTP Pass Through" or "VPN Pass Through" on consumer grade routers...
>
>Another alternative may be a SSH tunnel. I do that into my home LAN and use either Remote 
>Desktop/UltraVNC to access my XP Pro/Home desktops or WinSCP to transfer files to/from the home LAN 
>from a remote location... The SSH tunnel is encrypted end-to-end and is very easy to setup and use, 
>particularly for a home user.
>
>http://theillustratednetwork.mvps.org/RemoteDesktop/SSH-RDP-VNC/RemoteDesktopVNCandSSH.html
>
>In the case of SSH you need to forward TCP Port 22 through the firewall/NAT/router to the SSH 
>server's private LAN IP address.


Relevant Pages

  • Is this a wise configuration?
    ... First, I apologize if this is slightly OT for this NG, but I was unable to find a more general "networking" NG on my nntp server. ... I would like to create a separate "zone" on my network, autonomous from the private LAN, to place these servers in in order to minimize the security risk to the rest of the LAN. ... I would like the private LAN to be invisible to the "server zone", but still have access to the internet through the DSL router. ...
    (comp.os.linux.networking)
  • Re: IPSec VPN into XP Pro
    ... Al Jarvi (MS-MVP Windows Networking) ... >>any firewall/NAT/router at the server end to the private LAN IP of the PPTP VPN server. ... >>Another alternative may be a SSH tunnel. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Help w/ Not-booting Problem
    ... >No - setting the hostname is one element in the boot process. ... I have had a working system of RedHat Linux 7.2 for several months. ... >external DNS server on an adsl router! ... >You appear to have a networking problem. ...
    (comp.os.linux.misc)
  • Re: Fedora 6 - How to name machines on LAN for net?
    ... ohmster.ohmster.com ohmster #eth0 to Internet ... it is not necessary to route all traffic through the linux server. ... I want to learn Linux routing and networking so this is the reason that I ...
    (comp.mail.sendmail)
  • Re: SBS SP 1 installation error
    ... Component Name: Microsoft Exchange Forest Preparation ... Component Name: Server Configuration ... Component Name: Windows Server 2003 Configuration ... Component Name: Networking Configuration ...
    (microsoft.public.windows.server.sbs)