10.4.5 update and Cisco VPN support

The answer to this question might need to be provided by a developer.

Since the built in VPN client now supports Cisco VPN servers using NAT, does this mean that the VPN client now supports standard NAT Traversal?

Additionally, could someone tell me what Phase 1 and 2 proposals (including Diffie-Hellman group) are supported with the client and what the default key lifetimes are? Additionally, it would be nice to know if it is possible to modify the proposals.

Also, if I am setting up L2TP over IPSec, what is it actually sending for my username. Does it send an ASN1 style identity, or an FQDN?

If I can find out this information, I can post instructions on how to make it connect to most VPN servers/devices.

Thanks.

12 Powerbook 1.33, Mac OS X (10.4.4)

Posted on Feb 14, 2006 9:32 PM

Reply
1 reply

Feb 15, 2006 3:20 PM in response to Jay Austad

Ok, so here's what I have figured out so far:
Main mode (not aggressive)
P1: 3des-sha1 DH Group 2 lifetime 3600
P2: aes or 3des(not sure of the keylength on AES), sha1 or md5, lifetime 3600

I still do not know if the NAT traversal is standard. When trying to connect to a NetScreen gateway, I'm getting "No acceptable P1 proposals were found" on the NetScreen. However, I created a new P1 proposal that matches what I've found above.

Any ideas here? I need to know if the NAT-T support is standard.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

10.4.5 update and Cisco VPN support

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.