Help/Advice for VPN Newbie: IPsec/L2TP

eLinux

Member
Mar 6, 2003
191
0
0
Well...I'm attempting to set up VPN so that I can connect to my home network (primarily home computer) via VPN while at a WiFi hotspot or at school.

I've been tinkering and reading every howto, article, etc. that I can find about VPN. Throughout this process I've read about the "weaknesses" which PPTP might have and therefore I've decided I really want to get IPsec working.

Firstly, it seems I can connect fine when I use PPTP, and that was easy enough to set up. I have a Windows 2003 Server box downstairs which I use as a experimental system which I test things on: thus far this computer has been responsible for accepting the VPN connections.

However, I can't find a *really* good article to teach me how to create a VPN "host" for IPsec/L2TP connections. Considering this is a fairly private network and the data on it is sensitive enough for me to want to go through all this trouble, PPTP probably isn't going to cut it.

I can't figure out how to use the certificates and the other steps necessary to create and complete a IPsec/L2TP connection.

One last thing is that after all my testing is done, I'd like to have my *WINDOWS XP* box accepting the VPN connections: but again, I'd like to use IPsec/L2TP instead of PPTP, and I can't figure out how to do that using Windows XP...

Can anybody help me with this, or is there any great article on the web that walks someone through creating this type of scenario?

Thanks so much in advance!
 

eLinux

Member
Mar 6, 2003
191
0
0
I was afraid of that answer. ;)

Plus the computer I have that is running 2003 is not very powerful, and I hear that IPsec really taxes the CPU...

So this brings me to this question:

There were obvious problems with MS CHAP...how about MS CHAP v2? How much can I trust PPTP?

As I said, I'm pretty much looking for something that'll keep prying eyes out. I tried the VNC over an SSH tunnel, but that was a pain in the butt and I haven't gotten it to work the way I want it to...

I haven't really been able to find a specific article or white paper on how secure PPTP and MS CHAP v2 are...

Then again I've read that PPTP is quite widely used out there as a VPN technique.

What do you all think?
 

eLinux

Member
Mar 6, 2003
191
0
0
Further, maybe someone can help me with this question I'm having about the VPN conneciton/hosting...

I want it to be so that, at the *very* least, the *ONLY* type of authentication that is allowed is MS CHAP v2. However, I have been unable to a document which shows how to allow only an incoming connection that uses MS CHAP v2. Of course, the client can be set to use MS CHAP v2...but I want the host to refuse a connection that doesn't use it (and in addition to that, maximum encryption).

Anybody know how to do this?

Thanks :)