L2TP VPN without IPSec between Netscreen and Win2K

From: Joe Duehmig (jwduehmig_at_tekra.com)
Date: 10/08/03


Date: Wed, 8 Oct 2003 14:56:20 -0500

I am trying to establish a VPN tunnel between a Netscreen 25 and a Windows
2000 workstation. This is proof-of-concept and I do not have a certificate
to enable IPSec on the tunnel, so I am trying to get L2TP to work without
IPSec. Netscreen's documentation says this will work if you set the RasMan
Parameters registry entry to ProhibitIPSec. I've done this but see no
results. If I try to connect from the outside, I see no activity in the
Netscreen's logs. If I try from inside, I see a log entry reading "create a
l2tp tunnel" but the connection times out. At no time is there any entries
in the policy log, indicating that the tunnel is never established. Has
anyone been able to get this to work?
Thanks,
Joe