only_networking Posted April 29, 2005 Report Share Posted April 29, 2005 Hi All,I'm a newbie here, just wondered if I could draw upon your knowledge of windows and ask the following;I'm working with a client who wishes to setup multiple VPN's over their internal network's terminating on a firewall (FortiNet). They use one set of VPN's with PPTP, whilst their more secure is using IPSEC/L2TP.The only issue is that the IPSec/L2TP isn't supported natively on the firewall - either/or but not both simultaneously in the same connection.So this leads me into the query - is there a way to get Windows 2000/XP to use purely IPSec WITHOUT having to use a separate client - this has already been vetoed by the client.HELP!Thanks in advance. Quote Link to comment Share on other sites More sharing options...
scuzzman Posted April 29, 2005 Report Share Posted April 29, 2005 I'm not too much into IPSec, but this might be of assistanceCLICK ME. Quote Link to comment Share on other sites More sharing options...
only_networking Posted April 29, 2005 Author Report Share Posted April 29, 2005 I'm not too much into IPSec, but this might be of assistanceCLICK ME.Scuzzman,Thanks for this, unfortunately I already had this information, I need to define whether there is an option to run purely IPSec (which all current resource's seem to point toward a negatory response).Thanks for your help though! Quote Link to comment Share on other sites More sharing options...
scuzzman Posted April 29, 2005 Report Share Posted April 29, 2005 Well, I found this on a page, but I'm having trouble finding how to do it:IPSec and L2TP are combined to provide both tunneling and security for IP, IPX and other protocol packets across any IP network. IPSec can also perform tunneling without L2TP, but it is only recommended for interoperability, when one of the gateways does not support L2TP or PPTP.This was the source document: http://www.microsoft.com/windows2000/en/ad...IPSECtunnel.htm Quote Link to comment Share on other sites More sharing options...
scuzzman Posted April 29, 2005 Report Share Posted April 29, 2005 I think I hit pay dirt:You can use IP Security (IPSec) in tunnel mode to encapsulate Internet Protocol (IP) packets and optionally encrypt them. The primary reason for using IPSec tunnel mode (sometimes referred to as "pure IPSec tunnel") in Microsoft Windows 2000 is for interoperability with third-party routers or gateways that do not support Layer 2 Tunneling Protocol (L2TP)/IPSec or PPTP Virtual Private Networking (VPN) tunneling technology.See here: http://support.microsoft.com/?kbid=252735 Quote Link to comment Share on other sites More sharing options...
only_networking Posted April 29, 2005 Author Report Share Posted April 29, 2005 I think I hit pay dirt:You can use IP Security (IPSec) in tunnel mode to encapsulate Internet Protocol (IP) packets and optionally encrypt them. The primary reason for using IPSec tunnel mode (sometimes referred to as "pure IPSec tunnel") in Microsoft Windows 2000 is for interoperability with third-party routers or gateways that do not support Layer 2 Tunneling Protocol (L2TP)/IPSec or PPTP Virtual Private Networking (VPN) tunneling technology.See here: http://support.microsoft.com/?kbid=252735That looks good info to me Scuzzman, I assume that this would also work with standard desktop also, the firewall will operate with IPSec in both modes, so this could well fulfill our requirements. Do you know if the similar approach would work with XP? Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted April 29, 2005 Report Share Posted April 29, 2005 The instructions given should work with Windows XP. There may be the odd renamed option, or it may be located in a different place.If you have any troubles, please post back. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted May 4, 2005 Report Share Posted May 4, 2005 It appears from this Microsoft Knowledge Base Articlehttp://support.microsoft.com/default.aspx?...kb;en-us;818043 that it is possible in XP SP2 systems, but it is my experience that IPSec isn't implemented well across different vendors. I'd strongly recommend using a client built by the company making the Firewall/VPN Device you're terminating to. I've also never tried it yet with the native 2000 or XP VPN Client software. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.