W2K vpn client to Cisco 3005 VPN concentrator

W2K vpn client to Cisco 3005 VPN concentrator

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
W2K vpn client to Cisco 3005 VPN concentrator srp336 06-20-2005
Posted by on June 20, 2005, 3:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


I've got a project to configure a Cisco 3005 vpn concentrator to allow
connections from the w2k builtin vpn client.

The concentrator currently has users connecting via the Cisco client
using IPSec, and authenticating against an Active Directory server.

The way I understand things is, PPTP is supported, but only without
encryption when authentication against Active Directory. And the only
other option is L2TP/IPSec, which is mutually exclusive with the
IPsec-only that's currently in use. (Have I got this all correct?)

So, the only option open here is PPTP without encryption, correct?

Is there any way to get the w2k client to do l2tp without ipsec?

Thanks!



Network Magic 20% Off NMEASY coupon code spring banner 468x60
Posted by on June 21, 2005, 6:50 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Yes, you can connect to a Cisco VPN concentrator using L2TP alone or
L2TP/IPsec.

By default, W2K creates an IPsec policy for L2TP that relies on digital
signature (digital certificate) authentication. So, if you want to
configure either L2TP alone or L2TP/IPsec with pre-shared key
authentication then you need to modify the registry.

Take a look at this article for more:

http://support.microsoft.com/kb/240262


By creating the 'ProhibitIpSec' value, and setting the value to '1' (as
discussed in the first part of the article), you actually disable the
automatic creation of an IPsec policy (using digitial signature auth)
for L2TP. So, if you don't want to use IPsec with L2TP, you can stop
there, without following the instructions in the rest of the article
(although you should consider the security implications!).


Hope that helps,

Mark

CCIE#6280 / CCSI#21051 / JNICS#121 / etc.

Author: www.ciscopress.com/1587051044



Posted by on June 21, 2005, 11:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options


I've gotten l2tp working with the w2k client and cisco vpn 3005, but it
looks like the same problem I was having with pptp.

Is there no way to connect with pptp or l2tp to a 3005 concentrator
with encryption, when that concentrator is authenticating against an
Active Directory server?



Posted by Anatoliy Mysnyk on June 22, 2005, 12:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Hello mark,

Tuesday, June 21, 2005, 4:50:41 PM, you wrote:

[skip]
> http://support.microsoft.com/kb/240262
> By creating the 'ProhibitIpSec' value, and setting the value to '1' (as
[skip]

Can the same problem be solved under Windows XP and Windows 2003?
Key 'ProhibitIpSec' does not work and I found no solution on MSDN site.

--
Best regards,
CiscoPress.ru
Anatoliy mailto:amysnyk@ciscopress.ru.no.spam.



Similar ThreadsPosted
Authentication problem with a Cisco 3005 concentrator April 28, 2005, 11:59 am
Cisco 3005 Concentrator + DLink 804HV Router July 20, 2005, 11:46 pm
Citrix access via VPN 3005 concentrator w/WebVPN January 12, 2006, 12:07 pm
Can't authenticate PPTP to a Cisco VPN 3005 June 16, 2005, 3:03 pm
Cisco VPN Concentrator and NAT November 10, 2005, 3:36 pm
Cisco Concentrator 3000 August 14, 2005, 7:03 pm
Cisco VPN 3000 concentrator November 29, 2007, 7:40 pm
cisco vpn connection to vpn concentrator 3000 not passing web traffic August 21, 2006, 11:44 pm
VPN 3000 Concentrator and Microsoft VPN Client March 5, 2006, 4:40 am
Watchguard / Safenet Client and Cisco VPN Client Compatible? February 7, 2005, 3:38 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map