Re: IPSec client from behind a NAT

From: Christopher Black [MSFT] (christb-nospam_at_microsoft.com)
Date: 07/22/04


Date: Thu, 22 Jul 2004 15:27:34 -0700

You need the NAT-T update for Windows XP (pre-SP2) to work though a NAT.

See http://support.microsoft.com/default.aspx?scid=kb;en-us;818043

  -- Chris

"Miha Pihler" <miha-news@atlantis.si> wrote in message
news:OYIEGWCcEHA.3012@tk2msftngp13.phx.gbl...
> What are you using for authentication? Kerberos, certificate, pre-shared
> key? Is this WinXP client part of same domain as Win2K3?
>
> Mike
>
> "Igor Dombrovan" <igor@chorus.com.ru> wrote in message
> news:%23s9hH6AcEHA.2340@TK2MSFTNGP10.phx.gbl...
>> Hi guys
>>
>> Anybody managed to configure an IPSec client (WinXP) to access a Win2K3
> from
>> behind a NAT ? I always get 547 event ID saying :
>> IKE security association negotiation failed.
>>
>> ...
>>
>> Failure Point:
>>
>> Me
>>
>> Failure Reason:
>>
>> No policy
>>
>> The policy is there, I bet. Google doesn't help at this time.
>>
>>
>>
>> Thanks
>>
>> Igor
>>
>
>



Relevant Pages

  • Re: IPSec & Kerberos
    ... There are three authentication methods for ipsec - kerberos, ... certificate is not required for authentication. ...
    (microsoft.public.win2000.networking)
  • Re: All accounts get locked out!
    ... I am going through the same trouble now...I get alot of NTLM authentication ... Kerberos logging. ... I have checked the Domain Security Policy as well as the ... > Logon Failure: ...
    (microsoft.public.win2000.security)
  • Is it possible to require both a certificate and a Kerberos password for authentication?
    ... My problem is that I don't trust my users to validate the server certificate - I know that ignorant muppets will accept a man in the middle attack without any worries as long as it gives them access to our network. ... But I don't want to rely entirely upon the certificate, because I don't trust the users to look after it and don't want the users to have to remember both a certificate passphrase and their kerberos password. ... What I want is to require two different methods of authentication. ...
    (comp.security.ssh)
  • Re: Is it possible to require both a certificate and a Kerberos password for authentication?
    ... Authentication is username & password via kerberos. ... My problem is that I don't trust my users to validate the server ... So I'd like to refuse access to clients that do not provide a certificate.. ... What I want is to require two different methods of authentication. ...
    (comp.security.ssh)
  • more than one certificate in a policy
    ... a client for a WSE web service with X-509 authentication. ... I have to configure a policy file using more than one digital certificate. ...
    (microsoft.public.dotnet.framework.webservices)

Loading