Windows 2000 supports only L2TP with IPSec transport mode for remote access or branch office. (L2TP cannot be used without IPSec.) It supports only RSA Digital Certificates for IPSec transport authentication with the gateway. Windows 2000 Professional Server or Advanced Server can act as a Windows 2000 L2TP/ IPSec client to a gateway server.
To configure L2TP over IPSec on the gateway:
Users page and enter an L2TP user ID and password.
Certificates page. This request can be transferred to a CA server that issues the certificate. The certificate can then be installed from the same page.
Certificates page. If the Windows 2000 certificate is issued by a different CA, you must also install its certificate.
Certificates page and select the Enable Allow All Feature check box. For the CA that issued the Windows 2000 certificate, select the Allow All Enabled check box. Select a user group from the Default Group pull-down. Be sure the user group selected has Allow IPSec Transport enabled and configured (not inherited) in its IPSec group properties. This configuration is very useful when L2TP user accounts are in RADIUS, since no L2TP or IPSec transport information needs to be stored in the LDAP server per user.|
128-bit AES |
ESP-AES with SHA1 Integrity |
|
Triple DES |
ESP-Triple DES with SHA1 Integrity ESP-Triple DES with MD5 Integrity |
|
56-bit DES |
ESP-Triple DES with SHA1 Integrity ESP-Triple DES with MD5 Integrity ESP-56-bit DES with SHA1 Integrity ESP-56-bit DES with MD5 Integrity |
|
40-bit DES |
ESP-Triple DES with SHA1 Integrity ESP-Triple DES with MD5 Integrity ESP-56-bit DES with SHA1 Integrity ESP-56-bit DES with MD5 Integrity ESP-40-bit DES with SHA1 Integrity ESP-40-bit DES with MD5 Integrity |
|
Authentication only |
ESP-Triple DES with SHA1 Integrity ESP-Triple DES with MD5 Integrity ESP-56-bit DES with SHA1 Integrity ESP-56-bit DES with MD5 Integrity ESP-40-bit DES with MD5 Integrity ESP-40-bit DES with SHA1 Integrity ESP-NULL (Authentication Only) with SHA1 Integrity ESP-NULL (Authentication Only) with MD5 Integrity AH-Authentication Only (HMAC-SHA1) AH-Authentication Only (HMAC-MD5) |
|
Not required |
ESP-Triple DES with SHA1 Integrity ESP-Triple DES with MD5 Integrity ESP-56-bit DES with SHA1 Integrity ESP-56-bit DES with MD5 Integrity ESP-40-bit DES with SHA1 Integrity ESP-40-bit DES with MD5 Integrity ESP-NULL (Authentication Only) with SHA1 Integrity ESP-NULL (Authentication Only) with MD5 Integrity AH-Authentication Only (HMAC-SHA1) AH-Authentication Only (HMAC-MD5) Data is allowed through even if it does not come through an IPSec transport with this data protection level. |