| Article: vtkb2316.htm |
| Difficulty: Difficult |
| Time to Complete (minutes): 60 |
| Last Updated: Apr 02, 2007 |
Question:
How do I configure a Virtual Private Network (VPN) to connect to the Virginia Tech Modem Pool via Layer 2 Tunneling Protocol (L2TP) over IP Security Protocol (IPSec) in Windows XP?
Answer:
To configure VPN over IPSec, you will need to edit your registry, set up IPSec, and then set up your L2TP connection.
-
Edit your registry to create the ProhibitIPSec Key.
-
From the Start menu, select Run.
-
In the Open text box, type: regedit
-
Click OK.
-
Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters.
-
From the Edit menu, select New, and then select DWORD Value. A text box will appear.
-
In the text box, type: ProhibitIPSec
-
Press the Enter key.
-
Double-click ProhibitIPSec.
-
In the Value Data text box, type: 1
-
Click OK.
-
Close the Registry Editor.
-
Restart your computer.
-
Download the IPSec policy file.
-
Go to Notes on Using Virginia Tech's VPN Pilot Service (https://rdweb.cns.vt.edu/~cgaylord/vpn/).
-
In the User Name text box, type: your PID.
-
In the Password text box, type: your PID password.
-
Click OK.
-
Click the W2k Ipsec Policy File for VPN link.
-
Save the file to your desktop.
-
Import the IPSec policy.
-
From the Start menu, select Control Panel.
-
Click the Performance and Maintenance link.
-
Click the Administrative Tools link.
-
Double-click the Local Security Policy icon.
-
In the left pane, select IP Security Policies on Local Computer.
-
From the Action menu, select All Tasks, and then select Import Policies.
-
From the Look In drop-down list, select Desktop.
-
Select the VT-VPN-Policy.ipsec file.
-
Click the Open button.
-
Select and assign the appropriate policy.
Note: For assistance, contact your network administrator.
-
To block the NetBIOS over TCP/IP (NBT) protocol: Right-click Encrypt VPN; Block NBT, and select Assign.
-
To allow the NetBIOS over TCP/IP (NBT) protocol: Right-click Encrypt VPN; Allow NBT, and select Assign.
-
Set up your L2TP connection.
-
From the Start menu, select Control Panel.
-
Click the Network and Internet Connections link.
-
Click the Network Connections link.
-
Click the Create a New Connection link.
-
Click Next.
-
Select the Connect to the Network at My Workplace option.
-
Click Next.
-
Select the Virtual Private Network Connection option.
-
Click Next.
-
In the Company Name text box, type: Virginia Tech L2TP Over IPSec
-
Click Next.
-
If present, select the Do Not Dial the Initial Connection option.
-
Click Next.
-
In the Host Name or IP Address text box, type: IPSec.cns.vt.edu
-
Click Next.
-
Select the Anyone's Use or My Use Only option.
-
Click Next.
-
Click Finish. The Connect to Virginia Tech L2TP Over IPSec window will open.
-
Click the Properties button.
-
Select the Security tab.
-
Select the Advanced option.
-
Click the Settings button.
-
Select the Allow These Protocols option.
-
Place a check in the Unencrypted Password (PAP) check box.
Note: Although your password will be sent unencrypted, the tunnel is encrypted through IPSec.
-
Click OK.
-
Click the Yes button.
-
Click the IPSec Settings button.
-
Place a check in the Use Pre-shared Key For Authentication check box.
-
In the Key text box, type: vatech
-
Click OK.
-
In the Virginia Tech L2TP Over IPSec window, click OK.
-
In the Username text box, type your PID.
-
In the Password text box, type your PID password.
-
Click the Connect button.