PC Review


Reply
Thread Tools Rate Thread

Chap V1 for VPN Connectivity

 
 
=?Utf-8?B?U2tpbGxtYWtlcg==?=
Guest
Posts: n/a
 
      20th Apr 2007
I understand that MS decided to deprecate Chap V1 on the VPN connectivity
options, and instead provide only Chap V2. So, instead of having two decent
encryption options available for VPN, MS decided to leave two non-encrypted
options, and delete a useful and supported Chap V1 encrypted option.

This severely impacts ANYONE that utilizes Cisco PIX firewalls (we use
several Pix 501 and 506 firewalls), since they are not capable of supporting
Chap V2.

This leaves us with the less than desireable options of using an unencrypted
PAP connection, not connecting at all, or REPLACING all of our PIX firewalls.

FOR GOODNESS SAKES, PLEASE MAKE CHAP V1 AVAILABLE AGAIN IN THE VPN
CONNECTION. WHY WOULD MS MAKE THE DECISION TO REMOVE A FUNCTIONAL ENCRYPTION
STANDARD AND REPLACE IT WITH ONE THAT IS NOT FULLY SUPPORTED?

----------------
This post is a suggestion for Microsoft, and Microsoft responds to the
suggestions with the most votes. To vote for this suggestion, click the "I
Agree" button in the message pane. If you do not see the button, follow this
link to open the suggestion in the Microsoft Web-based Newsreader and then
click "I Agree" in the message pane.

http://windowshelp.microsoft.com/com...orking_sharing
 
Reply With Quote
 
 
 
 
Sooner Al [MVP]
Guest
Posts: n/a
 
      20th Apr 2007
"Skillmaker" <(E-Mail Removed)> wrote in message
news:EE04E293-F727-4949-A029-(E-Mail Removed)...
>I understand that MS decided to deprecate Chap V1 on the VPN connectivity
> options, and instead provide only Chap V2. So, instead of having two
> decent
> encryption options available for VPN, MS decided to leave two
> non-encrypted
> options, and delete a useful and supported Chap V1 encrypted option.
>
> This severely impacts ANYONE that utilizes Cisco PIX firewalls (we use
> several Pix 501 and 506 firewalls), since they are not capable of
> supporting
> Chap V2.
>
> This leaves us with the less than desireable options of using an
> unencrypted
> PAP connection, not connecting at all, or REPLACING all of our PIX
> firewalls.
>
> FOR GOODNESS SAKES, PLEASE MAKE CHAP V1 AVAILABLE AGAIN IN THE VPN
> CONNECTION. WHY WOULD MS MAKE THE DECISION TO REMOVE A FUNCTIONAL
> ENCRYPTION
> STANDARD AND REPLACE IT WITH ONE THAT IS NOT FULLY SUPPORTED?
>
> ----------------
> This post is a suggestion for Microsoft, and Microsoft responds to the
> suggestions with the most votes. To vote for this suggestion, click the "I
> Agree" button in the message pane. If you do not see the button, follow
> this
> link to open the suggestion in the Microsoft Web-based Newsreader and then
> click "I Agree" in the message pane.
>
> http://windowshelp.microsoft.com/com...orking_sharing


Have you seen this?

http://support.microsoft.com/kb/926170/en-us

--

Al Jarvi (MS-MVP Windows Networking)

Please post *ALL* questions and replies to the news group for the
mutual benefit of all of us...
The MS-MVP Program - http://mvp.support.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no
rights...

 
Reply With Quote
 
=?Utf-8?B?U2tpbGxtYWtlcg==?=
Guest
Posts: n/a
 
      21st Apr 2007
Yes, I have seen this. Again, the PIX firewalls do NOT support CHAP, they DO
support MS Chap V1. There are literally 10s of thousands of Cisco PIX
firewalls out there.

I can understand removing features that are no useful, but I cannot
understand removing features that WORK and are SUPPORTED in the industry.

What would be so difficult about putting MS Chap V1 back into the VPN
interface? The 'work arounds' suggested by Microsoft are garbage.

"Sooner Al [MVP]" wrote:

> "Skillmaker" <(E-Mail Removed)> wrote in message
> news:EE04E293-F727-4949-A029-(E-Mail Removed)...
> >I understand that MS decided to deprecate Chap V1 on the VPN connectivity
> > options, and instead provide only Chap V2. So, instead of having two
> > decent
> > encryption options available for VPN, MS decided to leave two
> > non-encrypted
> > options, and delete a useful and supported Chap V1 encrypted option.
> >
> > This severely impacts ANYONE that utilizes Cisco PIX firewalls (we use
> > several Pix 501 and 506 firewalls), since they are not capable of
> > supporting
> > Chap V2.
> >
> > This leaves us with the less than desireable options of using an
> > unencrypted
> > PAP connection, not connecting at all, or REPLACING all of our PIX
> > firewalls.
> >
> > FOR GOODNESS SAKES, PLEASE MAKE CHAP V1 AVAILABLE AGAIN IN THE VPN
> > CONNECTION. WHY WOULD MS MAKE THE DECISION TO REMOVE A FUNCTIONAL
> > ENCRYPTION
> > STANDARD AND REPLACE IT WITH ONE THAT IS NOT FULLY SUPPORTED?
> >
> > ----------------
> > This post is a suggestion for Microsoft, and Microsoft responds to the
> > suggestions with the most votes. To vote for this suggestion, click the "I
> > Agree" button in the message pane. If you do not see the button, follow
> > this
> > link to open the suggestion in the Microsoft Web-based Newsreader and then
> > click "I Agree" in the message pane.
> >
> > http://windowshelp.microsoft.com/com...orking_sharing

>
> Have you seen this?
>
> http://support.microsoft.com/kb/926170/en-us
>
> --
>
> Al Jarvi (MS-MVP Windows Networking)
>
> Please post *ALL* questions and replies to the news group for the
> mutual benefit of all of us...
> The MS-MVP Program - http://mvp.support.microsoft.com
> This posting is provided "AS IS" with no warranties, and confers no
> rights...
>

 
Reply With Quote
 
=?Utf-8?B?QmVuIENvb3Blcg==?=
Guest
Posts: n/a
 
      25th Sep 2007
I agree here, as we have the exact same problem. I checked with Cisco TAC
and they said since we are doing L2TP over IPSec, that PAP would be OK, since
it is all encrypted by IPSec first. Otherwise, PAP should be banned. It
should have been removed long before MSCHAPv1 was.

Regardless, the article referenced still doesn't address MSCHAPv1. MS needs
to either document a fix or better explain this one.



"Skillmaker" wrote:

> Yes, I have seen this. Again, the PIX firewalls do NOT support CHAP, they DO
> support MS Chap V1. There are literally 10s of thousands of Cisco PIX
> firewalls out there.
>
> I can understand removing features that are no useful, but I cannot
> understand removing features that WORK and are SUPPORTED in the industry.
>
> What would be so difficult about putting MS Chap V1 back into the VPN
> interface? The 'work arounds' suggested by Microsoft are garbage.
>
> "Sooner Al [MVP]" wrote:
>
> > "Skillmaker" <(E-Mail Removed)> wrote in message
> > news:EE04E293-F727-4949-A029-(E-Mail Removed)...
> > >I understand that MS decided to deprecate Chap V1 on the VPN connectivity
> > > options, and instead provide only Chap V2. So, instead of having two
> > > decent
> > > encryption options available for VPN, MS decided to leave two
> > > non-encrypted
> > > options, and delete a useful and supported Chap V1 encrypted option.
> > >
> > > This severely impacts ANYONE that utilizes Cisco PIX firewalls (we use
> > > several Pix 501 and 506 firewalls), since they are not capable of
> > > supporting
> > > Chap V2.
> > >
> > > This leaves us with the less than desireable options of using an
> > > unencrypted
> > > PAP connection, not connecting at all, or REPLACING all of our PIX
> > > firewalls.
> > >
> > > FOR GOODNESS SAKES, PLEASE MAKE CHAP V1 AVAILABLE AGAIN IN THE VPN
> > > CONNECTION. WHY WOULD MS MAKE THE DECISION TO REMOVE A FUNCTIONAL
> > > ENCRYPTION
> > > STANDARD AND REPLACE IT WITH ONE THAT IS NOT FULLY SUPPORTED?
> > >
> > > ----------------
> > > This post is a suggestion for Microsoft, and Microsoft responds to the
> > > suggestions with the most votes. To vote for this suggestion, click the "I
> > > Agree" button in the message pane. If you do not see the button, follow
> > > this
> > > link to open the suggestion in the Microsoft Web-based Newsreader and then
> > > click "I Agree" in the message pane.
> > >
> > > http://windowshelp.microsoft.com/com...orking_sharing

> >
> > Have you seen this?
> >
> > http://support.microsoft.com/kb/926170/en-us
> >
> > --
> >
> > Al Jarvi (MS-MVP Windows Networking)
> >
> > Please post *ALL* questions and replies to the news group for the
> > mutual benefit of all of us...
> > The MS-MVP Program - http://mvp.support.microsoft.com
> > This posting is provided "AS IS" with no warranties, and confers no
> > rights...
> >

 
Reply With Quote
 
=?Utf-8?B?R3JlZw==?=
Guest
Posts: n/a
 
      17th Oct 2007

Please, this is awful. I have to carry around two laptops - one with XP and
my new one just so we can continue to work on our clients that use Chap V1.
Come on. Get with the program MSFT! Also, how about getting copy / paste /
delete over shared networks working? Perhaps consider not limiting network
bandwidth when streaming?

Embarrassing effort. Would love to send you an invoice for the time and
money wasted on this product.

"Skillmaker" wrote:

> I understand that MS decided to deprecate Chap V1 on the VPN connectivity
> options, and instead provide only Chap V2. So, instead of having two decent
> encryption options available for VPN, MS decided to leave two non-encrypted
> options, and delete a useful and supported Chap V1 encrypted option.
>
> This severely impacts ANYONE that utilizes Cisco PIX firewalls (we use
> several Pix 501 and 506 firewalls), since they are not capable of supporting
> Chap V2.
>
> This leaves us with the less than desireable options of using an unencrypted
> PAP connection, not connecting at all, or REPLACING all of our PIX firewalls.
>
> FOR GOODNESS SAKES, PLEASE MAKE CHAP V1 AVAILABLE AGAIN IN THE VPN
> CONNECTION. WHY WOULD MS MAKE THE DECISION TO REMOVE A FUNCTIONAL ENCRYPTION
> STANDARD AND REPLACE IT WITH ONE THAT IS NOT FULLY SUPPORTED?
>
> ----------------
> This post is a suggestion for Microsoft, and Microsoft responds to the
> suggestions with the most votes. To vote for this suggestion, click the "I
> Agree" button in the message pane. If you do not see the button, follow this
> link to open the suggestion in the Microsoft Web-based Newsreader and then
> click "I Agree" in the message pane.
>
> http://windowshelp.microsoft.com/com...orking_sharing

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Include chap heading with chap title? Al Microsoft Word Document Management 1 29th Sep 2009 04:15 AM
MD-5 CHAP RB Microsoft Windows 2000 Networking 0 19th Nov 2003 05:24 PM
CHAP & Encryption myrt webb Microsoft Windows 2000 RAS Routing 1 20th Oct 2003 01:23 PM
How to authenticate user via MS-CHAP or MS-CHAP v2 from EAPMakeMessage Kim, Mungyu Microsoft Windows 2000 RAS Routing 0 23rd Sep 2003 06:19 AM
IPSEC vs MS-CHAP Myrt Webb Microsoft Windows 2000 Security 1 2nd Sep 2003 04:35 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:51 PM.