Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN with windows 2000 (L2TP)

Status
Not open for further replies.

erezohar

MIS
Joined
Mar 12, 2003
Messages
3
Location
US
I want to configure my pix firewall to work and establish vpn connection with windows 2000 clients using the built-in client with L2TP.

I tried to configure the pix but i think i am missing something. I am not using certificates.

Has anyone did that before

thanks

erez
 
HI.

It works fine with PPTP (at the pix called VPDN).
I did not try with L2TP, it should work but is more comlex then other solutions.

I recommend using Cisco IPSec VPN using Cisco client, because you can get better security using dual authentication (both vpngroup authentication and XAUTH radius) which makes it more dificult to break in.

Bye
Yizhar Hurwitz
 
Thanks Izhar,
I've noticed that l2tp in more complex and therefore i already configured PPTP.

Now i have two problems with PPTP:

1. when connecting to the VPN the client can't access the internet. What should i do to make the pix route packets to the internet?

2. When the client is behind a firewall using nat it can't connect.


About using Cisco IPSec VPN. I am having the problem with nat when using the cisco client. I am using ver 3.0.6. Will upgrading the client help.

thanks
 
HI.

> 1. when connecting to the VPN the client can't access the internet
At the client, go to the properties of the VPN connection (networking tab), and remove the option "use default gateway on remote network".

> 2. When the client is behind a firewall using nat it can't connect
Yap. That's a problem.
Contact the firewall administrator at the remote client side.
You'll have similar problems with IPSec behind NAT/firewall as well.

Bye
Yizhar Hurwitz
 
1. Doing so changes the routing table so everything is routed through the ISP and not through the VPN connection. Can't i use the VPN connection for browsing the internet too?

2. Suppose i am the administrator on the other network. What change should be done over there. Is the problem is with the NAT/PAT or with access rules?


thanks
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top