Rekey failure between Windows XP L2TP/IPSec and Cisco vpdn

Rekey failure between Windows XP L2TP/IPSec and Cisco vpdn

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Rekey failure between Windows XP L2TP/IPSec and Cisco vpdn Mike 07-27-2006
Posted by Mike on July 27, 2006, 10:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi

I have teleworkers that dial into our 837 vpdn server using the XP
L2TP/IPSec client.


Using the version of IOS I have IPSEC seems to prefer to rekey from the



vpdn server side.
This causes problems with firewalls nat etc.
The connections drops and needs to be re-establised.


The XP L2TP/IPSec client is hardwired to SA lifetime of 3600 secs (1
hr) so I can't increase that. I can't change IPSec SA lifetime on cisco



end as IPSec SA lifetime will always negotiate to the lowest value
between the 2 peers.


Is there anyway I can tell the vpdn server to leave rekey to the client



(like rekey=no for open swan). If re-key initiates from the client I
have no problems.


I can upgrade IOS is needed.


PS I have googled and cisco tech support until late into the night.
Hope I haven't missed the obvious.


Mike


using


Windows XP sp2 L2TP/IPSec with NAT-T update and all latest updates.
Cisco IOS Software, C837 Software (C837-K9O3SY6-M), Version 12.3(8)T3


Similar ThreadsPosted
Rekey failure between Windows XP L2TP?IPSec and Cisco vpdn July 27, 2006, 10:18 am
Reky Failure XP l2tp/ipsec client and vpdn July 27, 2006, 10:15 am
Ike phase 1 rekey & timeout March 18, 2008, 2:51 pm
Cisco ISO & FTP failure March 29, 2005, 9:08 pm
RDP thru Cisco VPN client and thru 501 Failure August 5, 2008, 3:52 pm
VPDN and VPM February 21, 2005, 10:55 pm
ADSL and VPDN April 12, 2005, 4:10 pm
Catalyst and VPDN. October 2, 2006, 5:34 am
VPDN Enable December 1, 2006, 10:10 am
PIX 501 vpdn debug help December 11, 2006, 10:15 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map