Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Building And Integrating Virtual Private Networks With Openswan (2006).pdf
Скачиваний:
73
Добавлен:
17.08.2013
Размер:
4.74 Mб
Скачать

Chapter 8

The settings in the Properties dialog include the WINS and DNS services, which allow host names that are only visible within the remote subnet to be resolved by the client. Also, if you do not want to tunnel all traffic through the VPN, you must uncheck the box labeled Use default gateway on remote network on the General tab.

When done, select OK and then Connect. This should bring the L2TP/IPsec connection up.

If you are receive 789 errors, double-check the hostname. If that's not the problem, try using an IP address. If you still get error 789, make sure that the IPsec service is not disabled and stopped.

There is one other possible problem with Windows XP SP2. Some people put the L2TP/IPsec server behind their firewall and use NAT or packet forwarding between the VPN and the firewall. We have not covered how to set this up, as it is not a recommended scenario, and in fact Windows XP Service Pack 2 disabled this possibility for XP as the client. You can re-enable it by tweaking the Windows registry and setting the following DWORD entry to 2:

HKLM\System\CurrentControlSet\Services\IPSec\AssumeUDPEncapsulationContextOnSe ndRule

Microsoft Windows 2000 L2TP Configuration

Windows 2000 can only be configured to use X.509 Certificates in combination with L2TP. The procedure is almost identical to the one described for Windows XP. Again, log in as a user that has administrative access to the local machine.

Open the Network Connection Wizard, found at Start | Programs | Accessories | Communications | Make New Connection. Click Next at the splash screen. Choose Connect to a private network through the Internet and click Next.

169

Interoperating with Microsoft Windows and Apple Mac OS X

Specify the gateway on the Destination Address screen, aivd.xelerance.com in our example, and select Next. The next screen is Connection Availability. Choose either For all users or Only for myself, depending on whether you want all users on this machine to be able to access the VPN.

On the last screen, give the connection a name and create a desktop shortcut if you desire, and then click Finish.

Connect to the VPN and fill in the username and password that was previously set in the CHAP secrets file. Save the username and password if you wish by checking the box. Do not start the connection yet, but first click the Properties button.

On the Options tab, tick Include Windows logon domain if you wish to log in to a remote Windows domain. Select the Security tab, and choose Advanced (custom settings), and click the Settings button.

170

Chapter 8

Select Optional encryption for the Data encryption dropdown. This refers to the L2TP encryption. As we are using L2TP/IPsec, we use IPsec for our encryption, and don't need to enforce encryption on the L2TP layer as well. Under Allow these protocols, make sure PAP is not selected and CHAP is selected and click OK.

A popup will appear, warning you that encryption (for L2TP) may not occur. Since we use IPsec, this isn't a problem, so click Yes. Now we are back in the connection menu, select the

Networking tab.

Change the Type of VPN server I am calling to Layer-2 Tunneling Protocol (L2TP).

171

Interoperating with Microsoft Windows and Apple Mac OS X

You can further configure the TCP/IP settings for the virtual IP that you will obtain by selecting Internet Protocol (TCP/IP) in the lower pane, and then clicking on Properties. Settings here include the WINS and DNS services, so that hostnames that are only visible within the remote subnet can be resolved by the client.

172