[Top] [Prev] [Next] [Bottom]
Page 29 out of 51 total pages
, Page 7 out of 8 pages in this chapter
Windows 2000 configuration
Windows 2000 Professional, Server or Advanced Server may act as a Windows 2000 L2TP/IPSec client to a gateway server. The steps for configuring the Windows 2000 side of this follow. To install a certificate on the Windows 2000 PC using a Windows 2000 Microsoft CA, connect to a CA server and get a certificate. This involves pointing a browser at the CA server with the URL <IP address>/certsrv.
- Choose Request a Certificate.
- Choose Advanced request.
- Submit a certificate request to this CA using a form.
- On the form provide the identifying information. This becomes the subject DN in the certificate that is entered on the gateway IPSec transport account.
- Choose IPSec Certificate as the Intended Purpose.
- Select Use local machine store under Key Options.
- When the certificate has been issued at the CA server, return to the first page.
- Choose Check on a pending certificate.
- Click Install this certificate. This installs the certificate in the local computer certificate store. To view this store, run the mmc command from the Start
Run prompt. Select Console
Add/Remove Snap-in. From the list of snap-ins, choose Certificates and select Computer account. At the console, expand Personal
Certificates under Certificates (Local Computer). The installed certificate should appear. Clicking on it brings up an information window that indicates its validity and that a private key exists for this certificate.
To install the CA server certificate for the Windows 2000:
- If the gateway's certificate was issued by a different CA, that server's certificate should also be installed. For the Microsoft CA, go back to the home page and select Retrieve the CA certificate or certificate revocation list.
- Click on the Install this CA certification path. This installs the CA certificate as a trusted CA, which can be seen in mmc under Trusted Root Certificates
Certificates.
To set up the dial-up networking entry to use L2TP over IPSec:
- Click on My Computer and click on Network and Dial-up Connections. Click on Make New Connection.
- Choose Connect to a private network through the Internet for the network connection type.
- Enter the interface address of the gateway server.
- Edit the properties of this new connection and select the Networking tab. Change the Type of VPN server to L2TP.
- Connect to the gateway using the L2TP user ID and password entered on the gateway. The certificate installed previously is automatically used to set up the IPSec transport connection.
[Top] [Prev] [Next] [Bottom]
Page 29 out of 51 total pages
, Page 7 out of 8 pages in this chapter
Configuring Tunneling Protocols and Advanced WAN Settings for the Contivity Secure IP Services Gateway