(racoon 819) Re: Windows XP Road Warrior with x509 and/or PSK

Roland Dirlewanger <[email protected]> Thu, 21 Oct 2004 10:36:01 +0200
Newsgroups gmane.network.ipv6.kame.racoon
Organization CNRS- Delegation Aquitaine et Poitou-Charentes, Bordeaux, France
Message-ID <[email protected]>
David Herselman wrote:

>2. I next tried getting x509 certificates to work with the Windows XP
>roaming machine. I've followed several documents on how to create the
>relevant certificates but none of them show the required steps in how one
>gets Windows XP to 'bind' the certificate to the required VPN connection...
>Windows XP doesn't even attempt the connection out as it can not locate the
>right certificate.
>
>I found some reference to a 'mini-HOWTO with Windows XP using certificates'
>but the domain doesn't exist anymore... Would someone possibly still have
>this document lying around? Broken link:
>http://www.fatcanary.com.au/docs/xp_freebsd_cert_ipsec.txt
>  
>
Jacco De Leeuw wrote a very good step by step guide for installing and 
configuring FreeSwan  with L2TP/IPsec clients. The part concerning the 
clients is not tighted to any ISAKMP or IPsec implementation. It 
contains a chapter named "Importing certificates (Windows 2000/XP)" in 
the following page :

http://www.jacco2.dds.nl/networking/win2000xp-freeswan.html

>Problem is that both the host and the client machine are on Dynamic IPs so I
>can not simply use the local security policy to activate the certificate on
>the IPSec link based on the IP filter...
>  
>
Your racoon.conf has  "generate_policy on" in phase 1. On a server with 
a fixed address, this  generates the correct policy, so there's no need 
to bother with setting the policy in  any other script. IMHO, it should 
also work in your case.

Roland.

-- 
Roland Dirlewanger
CNRS - Delegation Aquitaine et Poitou-Charentes
Esplanade des Arts et Metiers
33402 TALENCE CEDEX

Mel : [email protected], Tel : 05.57.35.58.52, Fax : 05.57.35.58.01