Re: L2TP setup

Tech-Archive recommends: Speed Up your PC by fixing your registry



Thanks Charlie. I've only got R1, does it make any difference (except
the IAS part) ?

Would using L2TP overcome any NATing issues which stop PPTP from working?


Charlie Russel - MVP wrote:

This is covered extensively in chapter 15 of our SBS R2 book, but the basic
steps are:
1.) Install IAS
2.) Open the IAS console and disable MS-CHAP, and set the encryption to use
128-bit only.
3.) Install Certificate Services (the self signed cert that SBS creates
isn't the right one for L2TP.)
4.) Create an enterprise root CA.
5.) Create local computer and current user Certs
6.) Create a server cert for the SBS server
7.) Deploy the certs in steps 5 and 6 to the VPN client(s) and the SBS
server respectively.
8.) Modify the SBS Remote Access Policy to allow authentication via
certificates (this is in the IAS console)
9.) Set the EAP method to Smart Card or other Cert and use the SBS server
cert you created in 6.
10.) Open the ports required in the RRAS console (IKE, IKE NAT Traversal,
and L2TP/IPSec)
11.) Enable EAP in RRAS
12.) Add L2TP ports in RRAS.

There are thirteen pages on this in chapter 15. And another batch in
chapter
16 if you're using ISA 2k4. It's not trivial, but is possible if you follow
the steps exactly. Unfortunately, all the steps are actually required.

.



Relevant Pages

  • Cert Error
    ... Trusted Cert Woes on SBS 2008 ... Les Connor wrote: ...
    (microsoft.public.windows.server.sbs)
  • Re: Cert Error
    ... Exchange 2007 UC/SAN Certificate ... have the subject alternative name listed on the cert for the server name. ... Windows 2008 sbs issue. ... Trusted Cert Woes on SBS 2008 ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS 2003 and Outlook RPC over HTTP issues
    ... Your cert is barfing due to the fact that the names do not match. ... some weird certificate error now though...if you want to see it ... As pointed out by others, port 80 does NOT need to be open, and yes, ... record pointing that to your SBS, and you have port 443 open and ...
    (microsoft.public.windows.server.sbs)
  • Re: L2TP VPN
    ... Install Certificate Services (the self signed cert that SBS creates isn't the right one for L2TP.) ... I created a connection manually. ...
    (microsoft.public.windows.server.sbs)
  • Re: PEAP auth with Verisign
    ... I'd also make sure that the client machine trusts the cert chain. ... You mentioned a root server cert that is generated by IAS. ... >I purchased a Verisign Class 3 WLAN server certificate ...
    (microsoft.public.internet.radius)