cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
404
Views
0
Helpful
2
Replies

Windows Vista: changes in ISAKMP

yuri.volkov
Level 1
Level 1

Has anybody experienced problems with Windows Vista? We have hundreds of customers which successfully connect to our Cisco router from Windows XP. They manually (via wizard) create VPN-connection using their login, pswd and preshared key (all other settings are set to defaults). Router is configured to use transport mode, l2tp, 3DES, MD5, DH group 2, and a preshared key. But when they try to establish the same VPN-connection on Vista they most often get error 789 (negotiation failed). May be there is some new policy or enabled option which affects ISAKMP in Windows Vista?

2 Replies 2

yuri.volkov
Level 1
Level 1

The problem proved to be simple: we had only one ISAKMP policy (encryption: 3DES, hash: MD5) and it was o.k. with Windows XP. But in Windows Vista MD5 is removed. Though it's possible to get back MD5 by editing registry of operating system, we just added another ISAKMP policy with "Secure Hash Standard" istead of "Message Digest 5" as hash algorithm.

For more details see: http://blogs.technet.com/rrasblog/archive/2006/11/01/vista-lh-security-changes-for-remote-access-scenarios.aspx

Thank's for the info!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: