RE: [suse-security] IPSEC - WIN2000
This is a late reply, but it may be interesting to some people nevertheless.
We are using IPSEC (on SuSE 7.0) already for a VPN to another location of our company. I would like to setup the IPSEC gateway also to handle road warriors which are using Win2000 machines.
I read that - PGPnet is not available for Win2000 - version 1.4 of IPSEC (which is on the 7.0 distribution) should be patched to work with PGPnet. Are both statements correct?
PGPnet is available for W2K. There appear to have been bugs in previous versions, but PGP 7.1 is reported to be fixed. We're using it to connect to FreeS/WAN on SuSE 7.2 in our lab successfully (at least partially). I don't know about FreeS/WAN 1.4, though.
Does anyone have experiences with other ipsec clients than PGPnet for Win2000? Which are available for Win2000? Which are recommended for Win2000?
The only IPSec implementation that we tested on W2K was its native IPSec support. Which, basically, didn't work. W2K professional doesn't support tunnel mode and W2K IPSec insists on setting the commit bit in part of the IKE negotiation. It may work without IKE and there's a patch for FreeS/WAN to ignore the commit bit instead of refusing to continue, but we needed tunnel mode and the W2K professional release, so we dumped native W2K IPSec and continued with PGPNet. Cheers Tobias
* Reckhard, Tobias wrote on Mon, Oct 01, 2001 at 08:12 +0200: [...]
The only IPSec implementation that we tested on W2K was its native IPSec support. Which, basically, didn't work. W2K professional doesn't support tunnel mode
Are you really sure about that? I know that the configuration with that MMC console is pretty mad [there are people who need a GUI - but I think that GUI is too confusing]. I made a simple interop. test with W2K/freeswan (W2K as road warrior connecting to secured networks behind a VPN gw) which worked. oki, Steffen -- Dieses Schreiben wurde maschinell erstellt, es trägt daher weder Unterschrift noch Siegel.
participants (2)
-
Reckhard, Tobias
-
Steffen Dettmer