Re: PPTP and NAT, IPSec and vpnc to Draytek Vigor



On Friday, May 18th, 2012, at 01:09:28h +0100, Chris Davies wrote:

2. My IPSec client of choice, vpnc, appears to make the Draytek router
complain about IKE being Aggressive and they won't play ball together.

Then it is time for you to consider dropping vpnc as your client of
choice because it is a client of limited ability and *only* supports
IKE aggressive mode.

My suggestion would be to look at Strongswan for setting up
an IPsec tunnel. If you become proficient with Strongswan
configuration, you will be able to setup connections of all
the different flavors that may be necessary with your various
customers.

<http://www.strongswan.ORG>

.



Relevant Pages

  • Re: NAT-T and L2TP
    ... I have already applied the update from q818043 to the w2k client ... IKE security association negotiation failed. ... > W2003 server. ...
    (microsoft.public.win2000.ras_routing)
  • Re: Problem with certificates/L2TP VPN
    ... of RRAS server. ... The client IS behind NAT. ... UDP 500 - for IKE ... Certificate based Identity. ...
    (microsoft.public.windows.server.networking)
  • Re: NAT-T and L2TP
    ... L2TP on our LAN but they fail from the internet. ... the second one from a client having a public IP address. ... IKE security association negotiation failed. ... Destination Port 0 ...
    (microsoft.public.win2000.ras_routing)
  • L2TP + NAT-T
    ... connect L2TP on our LAN, but they fail from the internet. ... from a NATted client, the second one from a client having ... IKE security association negotiation failed. ... Destination Port 0 ...
    (microsoft.public.win2000.ras_routing)
  • Re: Problem with certificates/L2TP VPN
    ... Looks like your are doing the right things, maybe the next test would be to run with IKE auditing switched on. ... Are you 100% sure authentication, encryption and key change are the same for both systems? ... EKU on client contains: Client Authentication ... EKU on server contains: Server Authentication ...
    (microsoft.public.windows.server.networking)