Welcome to WinForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Windows Vista PPTP vpn Cisco Pix 515E

 
Goto page Previous  1, 2, 3, 4, 5
   Windows XP Arc2 (Home) -> Work Remotely RSS
Next:  Disc Defrag cannot start  
Author Message
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 61) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: microsoft>public>windowsxp>work_remotely (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer.TakeThisOut@gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert

 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 62) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer RemoveThis @gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert

 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 63) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer.DeleteThis@gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 64) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer.RemoveThis@gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 65) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer DeleteThis @gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 66) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer RemoveThis @gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 67) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer.TakeThisOut@gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 68) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer.RemoveThis@gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 69) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer.RemoveThis@gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 70) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer.RemoveThis@gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
EricvanderMeer

External


Since: Nov 22, 2006
Posts: 70



(Msg. 71) Posted: Thu Nov 23, 2006 1:06 am
Post subject: Re: Windows Vista PPTP vpn Cisco Pix 515E [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Here's the solution for this problem:

VPN Improvement in Vista
Microsoft has changed the default settings for VPN connections to only
use MS-CHAP v2 for Authentication. If you are unfamiliar with the way
that PPTP (Microsoft Default) VPN connections work, well they are
established in a similar was as IPSec VPN's are. First, an
authentication session is established, second an encryption algorithm
is agreed upon. Microsoft's PPTP client has historically supported
four authentication methods for PPTP connections.
· PAP - Passwords are sent as clear ACSII text
· CHAP - Simple one-way hash sent to encrypt the password
· MS-CHAP (v1) - Same as CHAP except that it adds the
ability to change passwords, supports retry, and returns failure codes
explaining why an authentication failed.
· MS-CHAP v2 - adds mutual authentication by sending a
response challenge.
Windows XP supported all four for VPN authentication. Vista now
supports all but MS-CHAP (v1). This is interesting because if you are
using a Cisco PIX grade product, you should pay special attention to
this. You see the PIX's implementation of PPTP supports PAP, CHAP,
and MS-CHAP, but not MS-CHAP v2. This means that since Vista doesn't
support MS-CHAP and Cisco doesn't support MS-CHAP v2, you are left
with PAP and CHAP if your office or customer uses a Cisco PIX-based
product. Fortunately for you, PAP and CHAP are disabled by default, so
if you are using a PIX, you will need to manually configure your VPN
connection after creation.

EricvanderMeer RemoveThis @gmail.com schreef:

> Hello Robert,
>
> Same problem here, at work we have a same PIX device and i still cannot
> connect from my Vista Ultimate client.
>
> Tried everything but still no succes.
> Hope someone knows the solution for this problem.
>
> Best regards,
> Eric van der Meer
>
>
> Robert schreef:
>
> > Hi with my Windows XP I have no problem to connect to a cisco PIX 515E via
> > PPTP VPN tunnel. I dont even have to change anything on the encryption
> > settings and so on, only the option not to use default gateway on remote
> > network (Offcourse if this is what you want)
> > My question is what is different with Windows Vista?, I have tried
> > everithing with Vista, and I simply cannot connect to a PIX 515E over PPTP.
> > It seems the authentication mecanism has change in Windows Vista in contrast
> > to XP. (Is this right?) How can I connect to my PIX Firewall from a Windows
> > Vista Box?. Dont tell me now I have to buy some ridiculous licence!.
> > Best Regards,
> > Robert
 >> Stay informed about: Windows Vista PPTP vpn Cisco Pix 515E 
Back to top
Login to vote
Display posts from previous:   
   Windows XP Arc2 (Home) -> Work Remotely All times are: Eastern Time (US & Canada) (change)
Goto page Previous  1, 2, 3, 4, 5
Page 5 of 5

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
 Windows XP
 Windows Vista!
 Win 2000/NT/98/ME


[ Contact us | Terms of Service/Privacy Policy ]