PC Review


Reply
Thread Tools Rate Thread

VPN tunnel question

 
 
Miha
Guest
Posts: n/a
 
      5th Nov 2005
Hello



In our company we need to establish a secure VPN channel with outside
company in other country. They had already configured a VPN server (running
on WinNT) and sent us the following information so we could configure a VPN
client to connect.



Authentication method: pre-share secret

Key-change for encryption domain: yes



IKE (phase 1):

Encryption algorithm AES-256

'Condensation' function SHA-1

Diffie Helman group: 1024 bit

>Agressive mode< no


Key lifetime for phase1 1440 min



IKE (phase 2):

Encryption algorithm AES-256

'Condensation' function SHA-1

>Perfect Forward Secrecy enabled< no


PFS DH group: 1024 bit

>IP compression< no


>IPSEC SA Lifetime< 3600 s






I'm pretty confused of the information we got from them, because as far as I
know this aren't settings that could normally be configure for a VPN client.

Is this possible and how could be done or do we need to configure a
site-site VPN tunnel to achieve that kind of functionality.

I would be very thankful for all the information and tips how to do this

Thank you all in advance



Regards

Miha


 
Reply With Quote
 
 
 
 
Miha Pihler [MVP]
Guest
Posts: n/a
 
      5th Nov 2005
Information provided in used for Site-to-Site VPN.

--
Miha
Microsoft MVP - Windows Security

"Miha" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> Hello
>
>
>
> In our company we need to establish a secure VPN channel with outside
> company in other country. They had already configured a VPN server
> (running on WinNT) and sent us the following information so we could
> configure a VPN client to connect.
>
>
>
> Authentication method: pre-share secret
>
> Key-change for encryption domain: yes
>
>
>
> IKE (phase 1):
>
> Encryption algorithm AES-256
>
> 'Condensation' function SHA-1
>
> Diffie Helman group: 1024 bit
>
>>Agressive mode< no

>
> Key lifetime for phase1 1440 min
>
>
>
> IKE (phase 2):
>
> Encryption algorithm AES-256
>
> 'Condensation' function SHA-1
>
>>Perfect Forward Secrecy enabled< no

>
> PFS DH group: 1024 bit
>
>>IP compression< no

>
>>IPSEC SA Lifetime< 3600 s

>
>
>
>
>
> I'm pretty confused of the information we got from them, because as far as
> I know this aren't settings that could normally be configure for a VPN
> client.
>
> Is this possible and how could be done or do we need to configure a
> site-site VPN tunnel to achieve that kind of functionality.
>
> I would be very thankful for all the information and tips how to do this
>
> Thank you all in advance
>
>
>
> Regards
>
> Miha
>
>



 
Reply With Quote
 
 
 
 
Miha
Guest
Posts: n/a
 
      5th Nov 2005
Miha thank's for the reply.
Since on the other side they have a WinNT server, on our side it is a
Win2003 could there be any complications or is it better to implement also
at our side a WinNT server?
Regards
Miha

"Miha Pihler [MVP]" <mihap-(E-Mail Removed)> je napisal v sporočilo
news:(E-Mail Removed) ...
> Information provided in used for Site-to-Site VPN.
>
> --
> Miha
> Microsoft MVP - Windows Security
>
> "Miha" <(E-Mail Removed)> wrote in message
> news:%(E-Mail Removed)...
>> Hello
>>
>>
>>
>> In our company we need to establish a secure VPN channel with outside
>> company in other country. They had already configured a VPN server
>> (running on WinNT) and sent us the following information so we could
>> configure a VPN client to connect.
>>
>>
>>
>> Authentication method: pre-share secret
>>
>> Key-change for encryption domain: yes
>>
>>
>>
>> IKE (phase 1):
>>
>> Encryption algorithm AES-256
>>
>> 'Condensation' function SHA-1
>>
>> Diffie Helman group: 1024 bit
>>
>>>Agressive mode< no

>>
>> Key lifetime for phase1 1440 min
>>
>>
>>
>> IKE (phase 2):
>>
>> Encryption algorithm AES-256
>>
>> 'Condensation' function SHA-1
>>
>>>Perfect Forward Secrecy enabled< no

>>
>> PFS DH group: 1024 bit
>>
>>>IP compression< no

>>
>>>IPSEC SA Lifetime< 3600 s

>>
>>
>>
>>
>>
>> I'm pretty confused of the information we got from them, because as far
>> as I know this aren't settings that could normally be configure for a VPN
>> client.
>>
>> Is this possible and how could be done or do we need to configure a
>> site-site VPN tunnel to achieve that kind of functionality.
>>
>> I would be very thankful for all the information and tips how to do this
>>
>> Thank you all in advance
>>
>>
>>
>> Regards
>>
>> Miha
>>
>>

>
>



 
Reply With Quote
 
Steven L Umbach
Guest
Posts: n/a
 
      5th Nov 2005
That would be for an ipsec tunnel policy The link below may help. Phase 1
is also called main mode and phase 2 quick mode. Also Windows 2000 does not
support AES for ipsec. 3DES is the strongest it can use though if you have
an endpoint firewall device it might. --- Steve

http://support.microsoft.com/default...b;en-us;252735

"Miha" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> Hello
>
>
>
> In our company we need to establish a secure VPN channel with outside
> company in other country. They had already configured a VPN server
> (running on WinNT) and sent us the following information so we could
> configure a VPN client to connect.
>
>
>
> Authentication method: pre-share secret
>
> Key-change for encryption domain: yes
>
>
>
> IKE (phase 1):
>
> Encryption algorithm AES-256
>
> 'Condensation' function SHA-1
>
> Diffie Helman group: 1024 bit
>
>>Agressive mode< no

>
> Key lifetime for phase1 1440 min
>
>
>
> IKE (phase 2):
>
> Encryption algorithm AES-256
>
> 'Condensation' function SHA-1
>
>>Perfect Forward Secrecy enabled< no

>
> PFS DH group: 1024 bit
>
>>IP compression< no

>
>>IPSEC SA Lifetime< 3600 s

>
>
>
>
>
> I'm pretty confused of the information we got from them, because as far as
> I know this aren't settings that could normally be configure for a VPN
> client.
>
> Is this possible and how could be done or do we need to configure a
> site-site VPN tunnel to achieve that kind of functionality.
>
> I would be very thankful for all the information and tips how to do this
>
> Thank you all in advance
>
>
>
> Regards
>
> Miha
>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN tunnel question Miha Microsoft Windows 2000 File System 3 5th Nov 2005 05:12 PM
VPN tunnel question Miha Microsoft Windows 2000 3 5th Nov 2005 05:12 PM
VPN tunnel question Miha Microsoft Windows 2000 Group Policy 3 5th Nov 2005 05:12 PM
VPN tunnel question Miha Microsoft Windows 2000 RAS Routing 3 5th Nov 2005 05:12 PM
Redirecting VPN clients so they 'use' the VPN tunnel to access the Internet =?Utf-8?B?bm90ZWJlbmU=?= Microsoft Windows 2000 RAS Routing 1 31st Jan 2004 01:54 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:47 PM.