Re: IPSEC vs. PPTP, etc

From: Theodore F. Marz (tfm@sei.cmu.edu)
Date: 02/20/03


From: Theodore F. Marz <tfm@sei.cmu.edu>
Date: Thu, 20 Feb 2003 13:12:50 -0500

But, the combination of L2TP/IPSEC (ala Microsoft VPN) does NOT go
through NAT. Which was a problem for our organization.

We ended up using a Cisco VPN solution, which uses IPSEC, but does
IPSEC tunneling (TCP or UDP) to address certain VPN and Firewall
issues.

On Thu, 20 Feb 2003 17:20:40 +0000, Robert Mortimer
<rmortimerREMOVE@bluechiptechnology.co.uk> wrote:

>PPTP is no longer recommended by Microsoft for secure comms.
>It is tunnelling first secure second. That said it is good enough for
>most of us and it can go through a NAT.
>
>IPSEC is FBI and CIA proof (If set up correctly) byt it will not go
>through a NAT due to adjustments to the IP header
>
>L2TP Is Microsoft and co.'s second bite at the cherry. It will go
>through a NAT and if set up correctly should be secure.
>
>Rob
>
>Try the Free Swan Website
>
>On Tue, 26 Nov 2002 23:43:19 -0500, john <jpohn@amd.net> wrote:
>
>>What is more secure - IPSEC vs. PPTP, etc.
>>
>>Would anyone know of a good website that explains all this



Relevant Pages

  • Re: IPSEC vs. PPTP, etc
    ... PPTP is no longer recommended by Microsoft for secure comms. ... It is tunnelling first secure second. ... most of us and it can go through a NAT. ...
    (comp.security.firewalls)
  • Re: IPSEC vs. PPTP, etc
    ... > PPTP is no longer recommended by Microsoft for secure comms. ... > It is tunnelling first secure second. ... > most of us and it can go through a NAT. ...
    (comp.security.firewalls)
  • Re: how to open protocol 47 on a netscreen firewall?
    ... > It's not surprising that PPTP is not working across NAT. ... > should consider doing, if you insist on using Microsoft 'VPN', is use ... Do you have any pointers on setting up L2TP? ...
    (comp.security.firewalls)
  • Re: how to open protocol 47 on a netscreen firewall?
    ... > should consider doing, if you insist on using Microsoft 'VPN', is use ... ..which seems to be for allowing PPTP incoming through NAT. ...
    (comp.security.firewalls)
  • Re: NATting both ways
    ... on my "VPN" network off a PIX 525. ... We are using ip nat inside and ip nat outside on our inside and ... creates a VPN to another router on a remote network. ... crypto map CLIENTMAP client authentication list default ...
    (comp.dcom.sys.cisco)