L2TP VPN Connection Question

B

Buck Rogers

Hello,

I'm running XP SP2 and am trying to make a L2TP VPN connection to a
Cisco PIX501 at my office.

I'm not having great success and I've posted questions on Cisco's
newsgroup concerning the configuration of the PIX501.

My question here concerns setting up the VPN connection through XP.

A. Setup information background:

Home -> Cable modem -> Internet -> Work DSL Modem -> Cisco PIX501 ->
Server (I've taken my home router out of play to simplify).

Work DSL Modem IP = 1.1.1.30 Gateway (these numbers are for
explanation only)
Cisco PIX501 Outside Static IP = 1.1.1.29
Cisco PIX501 Inside IP = 10.0.0.1(internal gateway)
Server IP Inside = 10.0.0.2

B. I started the New Connection Wizard, checked connect to the
network at my workplace, checked VPN connection, gave it a name, told
it not to dial the initial connection, used 1.1.1.29 as the address of
the computer I am connecting to, my use only, and then click finish.
I then open the connection and go to VPN properties, go to the
security tab and check advanced (custom settings), click settings, use
require encryption, use allow protocols and check CHAP (I have this
set up on the PIX501), click IPSEC settings, enter the pre-shared key
and that appears to be all that needs to be configured on XP.

Where in all this configuration do I tell XP to use 3DES encryption,
MD5 authentication, and a DH Group = Group2 (1024bits). Cisco is
telling me I have to configure these items on the home computer before
I can get a connection to the PIX.

I've turned off the firewall at home to make sure that it won't get in
the way during this setup test.

I can't connect to work and would appreciate any input as to how I
configure XP to help me do so.

If I need to provide any further information, I will.

Regards,

Buck
 
R

Robert L [MS-MVP]

use portqry to test the port udp 500 is open or not. if it is, post the command lines here may help.

Bob Lin, MS-MVP, MCSE & CNE
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.
Don't send e-mail or reply to me except you need consulting services. Posting on MS newsgroup will benefit all readers and you may get more help.
Hello,

I'm running XP SP2 and am trying to make a L2TP VPN connection to a
Cisco PIX501 at my office.

I'm not having great success and I've posted questions on Cisco's
newsgroup concerning the configuration of the PIX501.

My question here concerns setting up the VPN connection through XP.

A. Setup information background:

Home -> Cable modem -> Internet -> Work DSL Modem -> Cisco PIX501 ->
Server (I've taken my home router out of play to simplify).

Work DSL Modem IP = 1.1.1.30 Gateway (these numbers are for
explanation only)
Cisco PIX501 Outside Static IP = 1.1.1.29
Cisco PIX501 Inside IP = 10.0.0.1(internal gateway)
Server IP Inside = 10.0.0.2

B. I started the New Connection Wizard, checked connect to the
network at my workplace, checked VPN connection, gave it a name, told
it not to dial the initial connection, used 1.1.1.29 as the address of
the computer I am connecting to, my use only, and then click finish.
I then open the connection and go to VPN properties, go to the
security tab and check advanced (custom settings), click settings, use
require encryption, use allow protocols and check CHAP (I have this
set up on the PIX501), click IPSEC settings, enter the pre-shared key
and that appears to be all that needs to be configured on XP.

Where in all this configuration do I tell XP to use 3DES encryption,
MD5 authentication, and a DH Group = Group2 (1024bits). Cisco is
telling me I have to configure these items on the home computer before
I can get a connection to the PIX.

I've turned off the firewall at home to make sure that it won't get in
the way during this setup test.

I can't connect to work and would appreciate any input as to how I
configure XP to help me do so.

If I need to provide any further information, I will.

Regards,

Buck
 
B

Buck Rogers

Robert,

Thanks for the reply.

The following is the output of portqry:

C:\Program Files\PortQryV2>portqry -n 192.168.1.6 -e 500 -p udp

Querying target system called:

192.168.1.6

Attempting to resolve IP address to a name...


IP address resolved to xxx.xxx

querying...

UDP port 500
Using source port UDP 500

Cannot use source port 500, this port is already in use
Remote ISAKMP/IPSec services may only communicate with source port 500
Temporarily turn off the 'IPSEC Policy Agent' or 'IPSEC Services'
on the system you are running PortQry from and run the command again


example: net stop PolicyAgent
run PortQry to query ISAKMP
net start PolicyAgent

C:\Program Files\PortQryV2>

Any other input?

I'll review the web links you suggested.

Thanks Again,

Buck
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top