<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: l2tp over IPSec scenario</title>
	<atom:link href="http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/</link>
	<description></description>
	<lastBuildDate>Sat, 03 Dec 2011 23:57:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: tnk</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/comment-page-1/#comment-626</link>
		<dc:creator>tnk</dc:creator>
		<pubDate>Wed, 22 Dec 2010 09:34:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77#comment-626</guid>
		<description>Hi Maksim,
it has been long time since I wrote this article and I am fairly sure it has been working then. I think the system was win XP (SP1 or maybe SP2?). But it is entirely possible that this does not work anymore on SP3/vista/win7. As I have no longer access to the equipment to test it I have no way of updating this article if it indeed does not work... If you have any more information I would appreciate that.
TNK</description>
		<content:encoded><![CDATA[<p>Hi Maksim,<br />
it has been long time since I wrote this article and I am fairly sure it has been working then. I think the system was win XP (SP1 or maybe SP2?). But it is entirely possible that this does not work anymore on SP3/vista/win7. As I have no longer access to the equipment to test it I have no way of updating this article if it indeed does not work&#8230; If you have any more information I would appreciate that.<br />
TNK</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maksim</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/comment-page-1/#comment-625</link>
		<dc:creator>Maksim</dc:creator>
		<pubDate>Wed, 22 Dec 2010 08:18:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77#comment-625</guid>
		<description>Hi,
with this registry it sure will not use IPSEC for L2TP client. You can check with wireshark (it will not even start IKE - udp 500, instead it will use udp 1701).</description>
		<content:encoded><![CDATA[<p>Hi,<br />
with this registry it sure will not use IPSEC for L2TP client. You can check with wireshark (it will not even start IKE &#8211; udp 500, instead it will use udp 1701).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tnk</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/comment-page-1/#comment-482</link>
		<dc:creator>tnk</dc:creator>
		<pubDate>Tue, 23 Mar 2010 14:27:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77#comment-482</guid>
		<description>Well this article has been written as a response to the people complaining that they cannot use Huawei routers as an VPN concentrator and that Huawei does not have any VPN client etc. I just used tools native to both Huawei and Windows to prove that such a configuration is possible. I believe that there is much more options of configuring and tweaking up both sides of the VPN.
As to your question - I don&#039;t fully understand what are you talking about but the thing is that you will create new interface on the host OS so it should be possible to adjust your routing table to allow certain prefixes go through the VPN and certain through the unencrypted connection.
But as I am no windows expert (and I have no intentions being one) I cannot tell for sure - it is just common sense that as the host OS decides what will go where so adjusting it should work. Anyway if you want to build an VPN concentrator you should buy a dedicated machine that was build for that purpose (Checkpoint&#039;s firewall with it&#039;s own client is one example or the Juniper&#039;s SSL solution which is great and widely used and there are others like FortiNet or even OpenVPN etc.)</description>
		<content:encoded><![CDATA[<p>Well this article has been written as a response to the people complaining that they cannot use Huawei routers as an VPN concentrator and that Huawei does not have any VPN client etc. I just used tools native to both Huawei and Windows to prove that such a configuration is possible. I believe that there is much more options of configuring and tweaking up both sides of the VPN.<br />
As to your question &#8211; I don&#8217;t fully understand what are you talking about but the thing is that you will create new interface on the host OS so it should be possible to adjust your routing table to allow certain prefixes go through the VPN and certain through the unencrypted connection.<br />
But as I am no windows expert (and I have no intentions being one) I cannot tell for sure &#8211; it is just common sense that as the host OS decides what will go where so adjusting it should work. Anyway if you want to build an VPN concentrator you should buy a dedicated machine that was build for that purpose (Checkpoint&#8217;s firewall with it&#8217;s own client is one example or the Juniper&#8217;s SSL solution which is great and widely used and there are others like FortiNet or even OpenVPN etc.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TKL</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/comment-page-1/#comment-481</link>
		<dc:creator>TKL</dc:creator>
		<pubDate>Mon, 22 Mar 2010 00:37:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77#comment-481</guid>
		<description>If it is very nice now, what was nice before? It is absurd as it gives no way of connecting clients to real network, so it requires routing which in fact disables usage for access of specific devices on a single subnet but nothing else.
In short - useless for anything else but default gateway vpn. Or am I missing anything?</description>
		<content:encoded><![CDATA[<p>If it is very nice now, what was nice before? It is absurd as it gives no way of connecting clients to real network, so it requires routing which in fact disables usage for access of specific devices on a single subnet but nothing else.<br />
In short &#8211; useless for anything else but default gateway vpn. Or am I missing anything?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tnk</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/comment-page-1/#comment-469</link>
		<dc:creator>tnk</dc:creator>
		<pubDate>Fri, 29 Jan 2010 16:24:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77#comment-469</guid>
		<description>OK so I checked with &lt;a href=&quot;http://support.microsoft.com/kb/240262&quot; rel=&quot;nofollow&quot;&gt;Microsoft knowledge-base&lt;/a&gt; and the thing is like this:
&quot;When the ProhibitIpSec registry value is set to 1, your Windows 2000-based computer does not create the automatic filter that uses CA authentication. Instead, it checks for a local or Active Directory IPSec policy.&quot;
which is actually what we need right ?</description>
		<content:encoded><![CDATA[<p>OK so I checked with <a href="http://support.microsoft.com/kb/240262" rel="nofollow">Microsoft knowledge-base</a> and the thing is like this:<br />
&#8220;When the ProhibitIpSec registry value is set to 1, your Windows 2000-based computer does not create the automatic filter that uses CA authentication. Instead, it checks for a local or Active Directory IPSec policy.&#8221;<br />
which is actually what we need right ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tnk</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/comment-page-1/#comment-468</link>
		<dc:creator>tnk</dc:creator>
		<pubDate>Fri, 29 Jan 2010 16:18:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77#comment-468</guid>
		<description>Well I think you might be right about that value. It seems more logical for it to be set to 0. I dug this from some very old script of mine and probably mixed the desired and default value :) Thanks for pointing that out I&#039;ll verify it and update the article.</description>
		<content:encoded><![CDATA[<p>Well I think you might be right about that value. It seems more logical for it to be set to 0. I dug this from some very old script of mine and probably mixed the desired and default value :) Thanks for pointing that out I&#8217;ll verify it and update the article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mHuba</title>
		<link>http://www.kuncar.net/blog/l2tp-over-ipsec-scenario/2009/comment-page-1/#comment-467</link>
		<dc:creator>mHuba</dc:creator>
		<pubDate>Fri, 29 Jan 2010 16:06:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.kuncar.net/blog/?p=77#comment-467</guid>
		<description>Hi, this configuration dosn&#039;t encrypt anything !!!
Tunel work without IPSec, You some switchoff this protocol on Windows ;) by set reg Prohibit Ip Sec = 1 !!!!</description>
		<content:encoded><![CDATA[<p>Hi, this configuration dosn&#8217;t encrypt anything !!!<br />
Tunel work without IPSec, You some switchoff this protocol on Windows ;) by set reg Prohibit Ip Sec = 1 !!!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

