cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
369
Views
0
Helpful
2
Replies

Microsoft L2TP connection from behind PIX

cboykin
Level 1
Level 1

Hi,

I'm trying to get a Microsoft native L2TP VPN client to go from behind my PIX to a VPN site on the Internet. It doesn't work. My PIX is running PAT for the outbound connections. My client gets to the "Verifying username and password" stage and hangs.

Suggestions?

2 Replies 2

scoclayton
Level 7
Level 7

It's been a while since I screwed around with L2TP but I recall that one of the biggest limitations to L2TP is that the original packets cannot be NAT'ed at all. That is, not PAT'ed nor 1:1 NAT'ed. The packets have to arrive at the termination device unchanged. You may want to check into this and make sure my info is not outdated.

Hope this helps.

Scott

there is a ms update that provides some nat-t support to l2tp, but i have no idea how effective it is. i believe it is a separate download for win2k and xp, and is included in xp sp2

Review Cisco Networking for a $25 gift card