Re: L2TP/IPSec from XP client to Windows 2003 Server

From: Steven L Umbach (sumbach_at_nospam-ameritech.net)
Date: 01/26/04


Date: Mon, 26 Jan 2004 18:47:17 GMT

You assign the preshared key using the Routing and Remote Access Management
Console. Select the server/properties/security - check the box at the bottom
for allow custom ipsec policy and enter preshared key in the box below.
Enter the same preshared key in the XP vpn connectoid in
properties/security/ipsec settings where a box will pop up to enter the key.
See KB link below or more details. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;324258

"Paul" <anonymous@discussions.microsoft.com> wrote in message
news:C23D0412-405E-4C85-BE13-09255839B674@microsoft.com...
>
> Mr. Adare, I did follow those instructions, I still get the same error.
>
> Steven, I unassigned the security policy on the server and still get the
same error.
> I found a URL on how to configure preshared keys for 2000, not 2003, do
you have
> a URL for configuring preshared keys on 2003? Do you still need to tweak
the registry?
> The same preshared key has to be on the client and server, and you
configure the preshared key
> in the Security Policy on the server side, so you have to assign one, even
though you say you don't
> need one for L2TP to work. I tried it and it still didn't work. It gives
me a different
> error, ...time out...
>
> I'll take your advice Steven and try to get preshared keys working on a
local (on the same LAN segment) machine.
> Although I don't see how that's going to get me to the real solution of
using certificates.
>
> This is NOT simple, it should be simple.
>
> Thank you for your help, I hope neither one of you gives up on me. :-)
>
>



Relevant Pages

  • RE: L2TP VPN connection between XP Pro and Win 2003 RRAS
    ... and RRAS server and am getting the error I described: ... Server expects Kerberous and Client send preshared key. ...
    (microsoft.public.windows.server.networking)
  • Re: RAS IPSEC/L2TP and Preshared Key
    ... L2TP with preshared key ... > Had a little assistance with the Certificates setting this up thanks ... also trying to set up RAS standalone server to use a preshared key. ...
    (microsoft.public.win2000.ras_routing)
  • Re: RRAS and Preshared Key
    ... If I had lets say my server assigned with a public IP address and my client had a Nat address would this situation work? ... > preshared key on the client and server was by setting up a IPSEC policy. ...
    (microsoft.public.win2000.networking)
  • Re: Win2K vpn client using shared secret key
    ... I was hoping that I could use that as a starting point for getting a client ... For some reason the OS X server can't do PPTP properly (I was ... L2TP/IPSec with a preshared key? ... > on each end of the router connection. ...
    (microsoft.public.win2000.networking)