Re: VPN protocols



Alex,

Its quite an interesting and a broad question. The answers you would receive would not be unique however it will be good to understand the view points.

Since you donot want a specific VPN products, I will try to answer in non-technical language.

Factors :

1) Main point: amount of security needed for comunication?
Doesn't matter: Go for PPTP or L2TP
Must : IPSec or SSL

2) Will users be connecting while traveling/home i.e Remote Access solution ? or two company locations needs to communicate securely i.e. Site to Site ?
Remote Access: PPTP, L2TP, IPsec Client or SSL VPN
Site to Site: IPSec only !!!

3) Budget
less: PPTP or L2TP
good: IPSec or SSL. and if you need remote access, I would recommend SSL because your helpdesk would not get call for installing the IPSec Software, configuring it.In SSL VPN , all you need is your SSL compatible browser !

4) Choice between installing software vs browser based
Ok to install software of PC: IPsec
No ! I dont want any software or client : SSL
I dont want to install any software but if there is something in built ,I don't mind using it: PPTP, L2TP

5) Ease of configuring the VPN Gateways:
More of less equal ( cos you can find the configuration guides etc on internet ). IPSec with different OS can get into issues !

6) Number of users using VPN
less users: doesn't make business sense to invest in a vendor solution.So you would like to use something which would be inbuilt in windows. PPTP and L2TP can be used in such cases.
more users:If its a big rollout, you would definitely wanna go for either SSL or IPSec

7) Comparable Speed ( this is debatable, but below id my view).
IPSec is faster than SSL


Other factors could be: type of users ( techie or non-techie), ease of troubleshooting etc

Hope this helps. Please let me know if you have questions.

Thanks,
Aditya Govind Mukadam



Relevant Pages

  • Re: VPN server
    ... You have to choose either/both PPTP or L2TP (which uses IPSec) for the ... (Dial-in tab even though this is VPN) ...
    (microsoft.public.windows.server.active_directory)
  • Re: VPN aus Netz nach extern
    ... >Abhängig, ob PPTP oder L2TP erlaubt werden soll, sind die ... >Bei PPTP ist es der Port upd/1723 und das Protokoll! ... da L2TP IPSec als Verschlüsselung nutzt ... kann IPSec over NAT Traversal benutzt ...
    (microsoft.public.de.german.isaserver)
  • Re: IPSec <> L2TP/IPSEC
    ... >- L2TP und IPSec Einwahl ... Wobei das dann IPSEC over L2TP heisst. ... problemlos PPTP verwenden. ... Trabanten in den Router einwählen? ...
    (de.comp.security.misc)
  • RE: PPTP versus L2TP and possible attacks
    ... both L2TP and PPTP are tunneling protocols ... without any inherent encryption built in. ... But there is no question that IPSec based VPN are more ...
    (Focus-Microsoft)
  • Re: VPN works with PPC 2002, not PPC 2003
    ... Like you I want true ipsec so I can ditch my pptp server and connect ... I did try to make a vpn connection while cradled and it didn't work. ... > Movian for the original PPC. ...
    (microsoft.public.pocketpc)