Jump to content

Win IPSec


only_networking
 Share

Recommended Posts

Hi All,

I'm a newbie here, just wondered if I could draw upon your knowledge of windows and ask the following;

I'm working with a client who wishes to setup multiple VPN's over their internal network's terminating on a firewall (FortiNet).

They use one set of VPN's with PPTP, whilst their more secure is using IPSEC/L2TP.

The only issue is that the IPSec/L2TP isn't supported natively on the firewall - either/or but not both simultaneously in the same connection.

So this leads me into the query - is there a way to get Windows 2000/XP to use purely IPSec WITHOUT having to use a separate client - this has already been vetoed by the client.

HELP!

Thanks in advance.

Link to comment
Share on other sites

Well, I found this on a page, but I'm having trouble finding how to do it:

IPSec and L2TP are combined to provide both tunneling and security for IP, IPX and other protocol packets across any IP network. IPSec can also perform tunneling without L2TP, but it is only recommended for interoperability, when one of the gateways does not support L2TP or PPTP.

This was the source document: http://www.microsoft.com/windows2000/en/ad...IPSECtunnel.htm

Link to comment
Share on other sites

I think I hit pay dirt:

You can use IP Security (IPSec) in tunnel mode to encapsulate Internet Protocol (IP) packets and optionally encrypt them. The primary reason for using IPSec tunnel mode (sometimes referred to as "pure IPSec tunnel") in Microsoft Windows 2000 is for interoperability with third-party routers or gateways that do not support Layer 2 Tunneling Protocol (L2TP)/IPSec or PPTP Virtual Private Networking (VPN) tunneling technology.

See here: http://support.microsoft.com/?kbid=252735

Link to comment
Share on other sites

I think I hit pay dirt:
You can use IP Security (IPSec) in tunnel mode to encapsulate Internet Protocol (IP) packets and optionally encrypt them. The primary reason for using IPSec tunnel mode (sometimes referred to as "pure IPSec tunnel") in Microsoft Windows 2000 is for interoperability with third-party routers or gateways that do not support Layer 2 Tunneling Protocol (L2TP)/IPSec or PPTP Virtual Private Networking (VPN) tunneling technology.

See here: http://support.microsoft.com/?kbid=252735

That looks good info to me Scuzzman, I assume that this would also work with standard desktop also, the firewall will operate with IPSec in both modes, so this could well fulfill our requirements.

Do you know if the similar approach would work with XP?

Link to comment
Share on other sites

It appears from this Microsoft Knowledge Base Article

http://support.microsoft.com/default.aspx?...kb;en-us;818043

that it is possible in XP SP2 systems, but it is my experience that IPSec isn't implemented well across different vendors. I'd strongly recommend using a client built by the company making the Firewall/VPN Device you're terminating to. I've also never tried it yet with the native 2000 or XP VPN Client software.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy