<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Routing and Remote Access Blog</title><link>http://blogs.technet.com/b/rrasblog/</link><description>VPN articles - straight from Windows development team</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Provisioning VPN client settings using Group Policy</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/08/31/provisioning-vpn-client-settings-using-group-policy.aspx</link><pubDate>Mon, 31 Aug 2009 15:38:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3278219</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3278219</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/08/31/provisioning-vpn-client-settings-using-group-policy.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Problem:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Today, Microsoft VPN client can be configured in two ways as discussed in &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-1-configuring-remote-access-clients.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;this&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; article – a) in-built VPN client b) CM based VPN client. The first method requires end user to know the VPN settings and then create a VPN connection – which needs to be repeated by each user and prone to errors. The second method requires VPN server administrator to create a VPN connection package (called as CM profile) and then send to end user through some mechanism (like uploading to a web server). The end user then manually installs the CM profile. The problem in this mechanism is end user may forget to do the same step when the configuration changes and VPN server administrator has no way to automatically push the changes.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Solution:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In this article we will discuss a group policy (GP) based provisioning solution for Microsoft VPN client. The key point of this solution is that it &amp;nbsp;works as long as client machine is running following Windows OS releases: Windows XP, Windows 2003, Windows Vista, Windows Server 2008, Windows7, Windows 2008 R2. &lt;I&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The steps to create the VPN connection for a VPN server administrator are fairly simple:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Configure all the settings required by VPN client (like VPN server hostname) in an XML file. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Place a powershell script and the above mentioned XML file in a file server location on the network . &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Create a group policy object (GPO) that points to network location containing the powershell script and XML file. Add the necessary end users/machines to the GPO.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Whenever the remote users logs on to their domain, they get group policy update and the VPN client gets created on their machine.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The details of the entire solution (along with the powershell script and sample XML file) can be seen &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=ce82bbd3-948b-476b-ab2e-1a1696349905"&gt;&lt;FONT size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How it works:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The solution involves following elements:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Remote access (RAS) APIs&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;PowerShell script and XML configuration file&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Group Policy&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The VPN server administrator configures a powerShell script to be run as a logon script in the Domain Controller. The instructions required for configuring VPN client settings are inside the script. The script takes the VPN client settings as input in form of a XML file which is configured by VPN server administrator. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;When a domain user logs on to the machine, the group policy settings get applied on the client. As part of that process, the powershell script is run. The script reads the configuration from XML file and configures the VPN client entries on the client machine by calling RAS APIs. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The end users can then use the VPN client connection to connect to VPN servers.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Let us know your feedback&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Cheers,&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Rama Krishna Prasad S&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Software Development Engineer&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Windows networking&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US; mso-bidi-language: AR-SA" lang=EN&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3278219" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Troubleshooting common VPN related errors</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/08/12/troubleshooting-common-vpn-related-errors.aspx</link><pubDate>Wed, 12 Aug 2009 14:27:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3272716</guid><dc:creator>rrasblog</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3272716</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/08/12/troubleshooting-common-vpn-related-errors.aspx#comments</comments><description>&lt;p align="left"&gt;Hello Customers,&lt;/p&gt;  &lt;p align="left"&gt;If you are seeing errors while establishing VPN connection using Windows in-built VPN client,&amp;#160; you have reached the right place. This article will help you to easily troubleshoot some of the common VPN related errors. &lt;/p&gt;  &lt;p align="left"&gt;1) &lt;u&gt;Error Code: &lt;strong&gt;800&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;The remote connection was not made because the attempted VPN tunnels failed. The VPN server might be unreachable. If this connection is attempting to use an L2TP/IPsec tunnel, the security parameters required for IPsec negotiation might not be configured properly.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This error comes when the VPN tunnel type is ‘Automatic’ and the connection establishment fails for all the VPN tunnels.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solutions:&lt;/b&gt;&lt;/p&gt;          &lt;p&gt;a&amp;gt; If you know which tunnel should actually be used for your deployment, try to set the ‘Type of VPN’ to that particular tunnel type on the VPN client side. [This can be set by clicking the ‘Network Connections’ icon on the bottom right of the task bar, Select your Connection, Right Click -&amp;gt; Properties -&amp;gt; Securities Tab -&amp;gt; Under ‘Type of VPN’ select the interested VPN tunnel type ]&lt;/p&gt;          &lt;p&gt;By making VPN connection with a particular tunnel type, your connection will still fail but it will give a more tunnel specific error (for example: GRE blocked for PPTP, Certificate error for L2TP, SSL negotiation errors for SSTP, etc.)&lt;/p&gt;          &lt;p&gt;b&amp;gt; This error usually comes when the VPN server is not reachable or the tunnel establishment fails.&lt;/p&gt;          &lt;p&gt;i. Make sure the VPN server is reachable (try to PING the server).&lt;/p&gt;          &lt;p&gt;ii. If interested in PPTP, make sure PPTP port (TCP 1723) or GRE Port (47) is not blocked on in between firewalls.&lt;/p&gt;          &lt;p&gt;iii. If interested in L2TP, make sure &lt;/p&gt;          &lt;p&gt;1. Correct pre-shared key or machine certificate are present both on client and server.&lt;/p&gt;          &lt;p&gt;2. L2TP port (UDP 1701) is not blocked on any of the firewalls.&lt;/p&gt;          &lt;p&gt;iv. If interested in IKEv2 based VPN tunnel, make sure &lt;/p&gt;          &lt;p&gt;1. IKE port (UDP port 500, UDP port 4500) is not blocked.&lt;/p&gt;          &lt;p&gt;2. Correct machine certificate for IKE are present both on client and server.&lt;/p&gt;          &lt;p&gt;v. If interested in SSTP, make sure correct machine certificate is installed on the server and correct trusted root certificate is installed on the client machine.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;2) &lt;u&gt;Error Code: &lt;strong&gt;609, 633&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="884"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;&lt;/p&gt;          &lt;p&gt;609: A device type was specified that does not exist.&lt;/p&gt;          &lt;p&gt;633: The modem (or other connecting device) is already in use or is not configured properly.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="884"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This error usually comes when the connecting VPN device (aka miniport) is not configured properly.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="884"&gt;         &lt;p&gt;&lt;b&gt;To confirm the issue: &lt;/b&gt;From the elevated command prompt, type the following command to confirm the presence of miniport: -&lt;/p&gt;          &lt;p&gt;netcfg.exe –q &amp;lt;miniport name&amp;gt;&lt;/p&gt;          &lt;p&gt;Following is the Miniport Device name for different tunnels:&lt;/p&gt;          &lt;p&gt;PPTP Tunnel: MS_PPTP&lt;/p&gt;          &lt;p&gt;L2TP Tunnel: MS_L2TP&lt;/p&gt;          &lt;p&gt;SSTP Tunnel: MS_SSTP&lt;/p&gt;          &lt;p&gt;VPN Reconnect (IKEv2) Tunnel: MS_AGILEVPN&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="884"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;&lt;/p&gt;          &lt;p&gt;1. In Windows 7, a built-in diagnostic with repair is provided for the ‘miniport missing’ issue for locally created VPN connections. A ‘Diagnostic’ button is shown on the Error page of the VPN connection. By clicking this button, it will give a ‘repair’ option if it finds the issue to be miniport missing which if clicked will automatically try to fix the issue.&lt;/p&gt;          &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;          &lt;p&gt;&lt;b&gt;&lt;a href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TroubleshootingmostcommonVPNerrors_CDFB/clip_image002_2.gif"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TroubleshootingmostcommonVPNerrors_CDFB/clip_image002_thumb.gif" width="483" height="149" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;          &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;          &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;          &lt;p&gt;2. On Vista or below OS, if the miniport device is missing, you can run the following command from ‘elevated’ command prompt:&lt;/p&gt;          &lt;p&gt;a&amp;gt; netcfg.exe -e -c p -i &amp;lt;miniport name&amp;gt;&lt;/p&gt;          &lt;p&gt;Details of the &amp;lt;miniport name&amp;gt; is given above.&lt;/p&gt;          &lt;p&gt;b&amp;gt; Stop and Start ‘rasman’ (‘Remote Access Connection Manager’) service.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;3) &lt;u&gt;Error Code: &lt;strong&gt;732, 734, 812&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;&lt;/p&gt;          &lt;p&gt;732: Your computer and the remote computer could not agree on PPP control protocols.&lt;/p&gt;          &lt;p&gt;734: The PPP link control protocol was terminated.&lt;/p&gt;          &lt;p&gt;812: The connection was prevented because of a policy configured on your RAS/VPN server. Specifically, the authentication method used by the server to verify your username and password may not match the authentication method configured in your connection profile. Please contact the Administrator of the RAS server and notify them of this error.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Causes: &lt;/b&gt;One of the prime causes for the above error&amp;#160; is: when the *only* allowed authentication protocol configured on VPN server (or Radius server) is MS-CHAP and the VPN client is Vista or above OS platform (like Windows7). Note: due to security reasons MS-CHAP was removed from Vista and above OS platform and hence the connection fails.&lt;/p&gt;          &lt;p&gt;Error 812 comes when Authentication protocol is set via NPS (Network Policy and Access Services) otherwise Error 732/734.&lt;/p&gt;          &lt;p&gt;Event log 20276 is logged to the event viewer when RRAS based VPN server authentication protocol setting mismatches which that of the VPN client machine.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Possible Solution: &lt;/strong&gt;Configure a more secured authentication protocol like MS-CHAPv2 or EAP based authentication on the server – which matches the settings on the client side.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;4) &lt;u&gt;Error Code: &lt;strong&gt;806&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description:&amp;#160; &lt;/b&gt;806: The VPN connection between your computer and the VPN server could not be completed. The most common cause for this failure is that at least one Internet device (for example, a firewall or a router) between your computer and the VPN server is not configured to allow Generic Routing Encapsulation (GRE) protocol packets. If the problem persists, contact your network administrator or Internet Service Provider.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;PPTP uses GRE (Generic Route Encapsulation) protocol to encapsulate the VPN payload in a secure manner.This error generally comes when some firewall in path between client and server blocks GRE Protocol (i.e. IP protocol number 47).&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Allow both outgoing and incoming Protocol 47 (GRE) on any in between firewalls. If that is not possible, deploy SSTP based VPN tunnel on both VPN server and VPN client – that allows VPN connection across firewalls, web proxies and NAT.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;5) &lt;u&gt;Error Code: &lt;strong&gt;789, 835&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;&lt;/p&gt;          &lt;p&gt;789: The L2TP connection attempt failed because the security layer encountered a processing error during initial negotiations with the remote computer.&lt;/p&gt;          &lt;p&gt;835: The L2TP connection attempt failed because the security layer could not authenticate the remote computer. This could be because one or more fields of the certificate presented by the remote server could not be validated as belonging to the target destination.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Causes: &lt;/b&gt;This is a generic error which is thrown when the IPSec negotiation fails for L2TP/IPSec connections.&lt;/p&gt;          &lt;p&gt;Possible causes for this issue could be:&lt;/p&gt;          &lt;p&gt;a&amp;gt; L2TP based VPN client (or VPN server) is behind NAT.&lt;/p&gt;          &lt;p&gt;b&amp;gt; Wrong certificate or pre-shared key is set on the VPN server or client&lt;/p&gt;          &lt;p&gt;c&amp;gt; Machine certificate or trusted root machine certificate is not present on the VPN server.&lt;/p&gt;          &lt;p&gt;d&amp;gt; Machine Certificate on VPN Server does not have 'Server Authentication' as the EKU&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Make sure correct certificate is used both on client and server side – for further details refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx"&gt;this&lt;/a&gt; blog. In case Pre Shared Key (PSK) is used, make sure the same PSK is configured on the client and the VPN server machine.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;6) &lt;u&gt;Error Code: &lt;strong&gt;766&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description:&amp;#160; &lt;/b&gt;766: A certificate could not be found. Connections that use the L2TP protocol over IPSec require the installation of a machine certificate, also known as a computer certificate.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This error usually comes when their is no valid machine certificate on your client machine.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Make sure the correct machine certificate for L2TP validation is installed on your client machine - for further details refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx"&gt;this&lt;/a&gt; blog.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;7) &lt;u&gt;Error Code: &lt;strong&gt;691&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;691: The remote connection was denied because the user name and password combination you provided is not recognized, or the selected authentication protocol is not permitted on the remote access server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This error is given when the authentication phase erred out because of wrong credentials being passed.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;&lt;/p&gt;          &lt;p&gt;a&amp;gt; Make sure correct username and password is typed.&lt;/p&gt;          &lt;p&gt;b&amp;gt; Make sure ‘Caps Lock’ is not turned ON while typing credentials.&lt;/p&gt;          &lt;p&gt;c&amp;gt;&lt;strong&gt; &lt;/strong&gt;Make sure the authentication protocol as selected on the client is permitted on the server.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;8) &lt;u&gt;Error Code: &lt;strong&gt;809&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;809: The network connection between your computer and the VPN server could not be established because the remote server is not responding. This could be because one of the network devices (e.g, firewalls, NAT, routers, etc) between your computer and the remote server is not configured to allow VPN connections. Please contact your Administrator or your service provider to determine which device may be causing the problem.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This error usually comes when some firewall between client and server is blocking the ports used by VPN tunnel&lt;/p&gt;          &lt;p&gt;a&amp;gt; PPTP port (TCP port 1723) is blocked by a firewall/router. [Applicable to tunnel type = PPTP]&lt;/p&gt;          &lt;p&gt;b&amp;gt; L2TP or IKEv2 port (UDP port 500, UDP port 4500) is blocked by a firewall/router. [Applicable to tunnel type = L2TP or IKEv2]&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Enable the port (as mentioned above) on firewall/router. If that is not possible, deploy SSTP based VPN tunnel on both VPN server and VPN client – that allows VPN connection across firewalls, web proxies and NAT.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;9) &lt;u&gt;Error Code: &lt;strong&gt;13806&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;13806: IKE failed to find valid machine certificate. Contact your Network Security Administrator about installing a valid certificate in the appropriate Certificate Store.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This usually happens when there is no machine certificate or no root machine certificate present on the VPN Server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Possible Solution: &lt;/strong&gt;Please contact your VPN server administrator to verify and fix the issue - for further details refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx"&gt;this&lt;/a&gt; blog.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;10) &lt;u&gt;Error Code: &lt;strong&gt;13801&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;13801: IKE authentication credentials are unacceptable.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Causes: &lt;/b&gt;This error usually comes in one of the following cases:&lt;/p&gt;          &lt;ol&gt;           &lt;li&gt;The machine certificate used for IKEv2 validation on RAS Server does not have 'Server Authentication' as the EKU (Enhanced Key Usage). &lt;/li&gt;            &lt;li&gt;The machine certificate on RAS server has expired. &lt;/li&gt;            &lt;li&gt;The root certificate to validate the RAS server certificate is not present on the client. &lt;/li&gt;            &lt;li&gt;VPN Server Name as given on client doesn’t match with the subjectName of the server certificate. &lt;/li&gt;         &lt;/ol&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Possible Solution: &lt;/strong&gt;Please contact your VPN server administrator to verify and fix the above issue - for further details refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx"&gt;this&lt;/a&gt; blog.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;11) &lt;u&gt;Error Code: &lt;strong&gt;0x800704C9&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description:&lt;/b&gt; &lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This issue may occur if no SSTP ports are available on the server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;To troubleshoot this issue, verify that the RAS server has sufficient ports configured for remote access. To do this, follow these steps: &lt;/p&gt;          &lt;ol&gt;           &lt;li&gt;Start the Routing and Remote Access MMC snap-in. &lt;/li&gt;            &lt;li&gt;Expand the server, right-click &lt;b&gt;Ports&lt;/b&gt;, and then click &lt;b&gt;Properties&lt;/b&gt;. &lt;/li&gt;            &lt;li&gt;In the Name list, click &lt;b&gt;WAN Miniport (SSTP)&lt;/b&gt;, and then click &lt;b&gt;Configure&lt;/b&gt;. &lt;/li&gt;            &lt;li&gt;Modify the number that appears in the &lt;b&gt;Maximum ports&lt;/b&gt; list, as appropriate for your requirements, and then click &lt;b&gt;OK&lt;/b&gt;.               &lt;br /&gt;&lt;b&gt;Note&lt;/b&gt; By default, 128 ports are available for this device. &lt;/li&gt;            &lt;li&gt;In the &lt;b&gt;Port Properties&lt;/b&gt; dialog box, click &lt;b&gt;OK&lt;/b&gt; &lt;/li&gt;         &lt;/ol&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;12) &lt;u&gt;Error Code: &lt;strong&gt;0x80070040&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Error Description: &lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This issue may occur if a server authentication certificate is not installed on the RAS server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Make sure the machine certificate used by RAS server for SSL has ‘Server Authentication’ as one of the certificate usage entries. For further details refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx"&gt;this&lt;/a&gt; blog. For changing the SSTP machine certificate, please refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/02/11/sstp-certificate-selection.aspx"&gt;this&lt;/a&gt; blog if on VPN server is running Windows server 2008 R2, else refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2007/11/08/do-you-want-to-change-the-certificate-used-by-the-sstp-server-read-how.aspx"&gt;this&lt;/a&gt; blog&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;13) &lt;u&gt;Error Code: &lt;strong&gt;0x800B0101&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Error Description: &lt;/strong&gt;0x800B0101: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This issue may occur if a server authentication certificate is not installed on the Routing and Remote Access server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Make sure the machine certificate used by RAS server for SSL has ‘Server Authentication’ as one of the certificate usage entries and the certificate is not expired. For further details refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx"&gt;this&lt;/a&gt; blog. For changing the SSTP machine certificate, please refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/02/11/sstp-certificate-selection.aspx"&gt;this&lt;/a&gt; blog if on VPN server is running Windows server 2008 R2, else refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2007/11/08/do-you-want-to-change-the-certificate-used-by-the-sstp-server-read-how.aspx"&gt;this&lt;/a&gt; blog&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;14) &lt;u&gt;Error Code: &lt;strong&gt;0x800B0109&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Error Description: &lt;/strong&gt;0x800B0109: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This issue may occur if the appropriate trusted root certification authority (CA) certificate is not installed in the Trusted Root Certification Authorities store on the client computer. &lt;/p&gt;          &lt;p&gt;&lt;b&gt;Note:&lt;/b&gt; Generally the VPN client machine is joined to the active directory based domain and if you use domain credentials to log on to the VPN server, the certificate is automatically installed in the Trusted Root Certification Authorities store. However, if the computer is not joined to the domain or if you use an alternative certificate chain, you may experience this issue.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Make sure root certificate is installed on the client machine in the Trusted Root Certification Authorities store.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;15) &lt;u&gt;Error Code: &lt;strong&gt;0x800B010F&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Error Description: &lt;/strong&gt;0x800B010F: The certificate's CN name does not match the passed value.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This issue may occur if the host name of the server that is specified in the VPN connection does not match the subject name that is specified on the SSL certificate that the server submits to the client computer.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;Verify that the certificate which RAS server uses for SSL has the correct subject name. For example, if the VPN client is configured to use FQDN name to connect to the VPN server, the certificate used by VPN server must have FQDN in the subject name. Same thing if the client is configured to use IP address (IPv4 or IPv6) of VPN server.&amp;#160; If the appropriately-named certificate is not present on the RAS server, you must obtain a new certificate for the RAS server.&lt;/p&gt;          &lt;p&gt;For changing the SSTP machine certificate, please refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/02/11/sstp-certificate-selection.aspx"&gt;this&lt;/a&gt; blog if on VPN server is running Windows server 2008 R2, else refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2007/11/08/do-you-want-to-change-the-certificate-used-by-the-sstp-server-read-how.aspx"&gt;this&lt;/a&gt; blog&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;16) &lt;u&gt;Error Code: &lt;strong&gt;0x80092013&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Error Description: &lt;/strong&gt;0x80092013: The revocation function was unable to check revocation because the revocation server was offline.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This issue may occur if the client computer fails the certificate revocation check for the SSL certificate that the client computer obtained from the VPN server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Solution: &lt;/b&gt;To troubleshoot this issue, verify that the server that hosts the Certificate Revocation List (CRL) is available to the client – before VPN tunnel is established. This means that the CRL server is available to the client over the Internet because the client computer runs the CRL check during the establishment of the SSL connection and the CRL check query is sent directly to the CRL server. &lt;b&gt;&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;17) &lt;u&gt;Error Code: &lt;strong&gt;0x800704D4&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Error Description: &lt;/strong&gt;0x800704D4: The network connection was aborted by the local system&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This error comes when the hostname of the VPN server is not resolved by the forward proxy in-front of the VPN client. &lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Possible Solution: &lt;/strong&gt;Check your proxy settings inside the Internet explorer. If the settings are correct, please ensure you are able to access other web sites (e.g. &lt;a href="http://www.microsoft.com"&gt;www.microsoft.com&lt;/a&gt;) using the browser. If that also works through, try accessing the URI which SSTP uses internally i.e. &lt;a href="https://vpn_server_name/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/"&gt;https://vpn_server_name/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/&lt;/a&gt;&amp;#160; -&amp;#160; please replace vpn_server_name with actual VPN server name. If you see error “the website cannot be found” inside your browser, that validates the hostname resolution failure. If you know the IP address of VPN server, try connecting with that. Else contact your network administrator (who is responsible for managing the web proxy – most probably your ISP) – giving them the details of the problem (i.e. hostname resolution is failing for that particular hostname). &lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;18) &lt;u&gt;Error Code: &lt;strong&gt;0x80072746&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Error Description: &lt;/strong&gt;0x80072746: An existing connection was forcibly closed by the remote host.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;b&gt;Possible Cause: &lt;/b&gt;This error comes when the server machine certificate binding to HTTPS is not done on the VPN server OR the server machine certificate is not installed on the VPN server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="798"&gt;         &lt;p&gt;&lt;strong&gt;Possible Solution: &lt;/strong&gt;Please contact your VPN server administrator – to check whether relevant machine certificate is installed&amp;#160; on the VPN server. If installed correctly, check the HTTPS binding by running following command at the VPN server command prompt - “netsh http show ssl”. For further details, please refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2007/11/08/do-you-want-to-change-the-certificate-used-by-the-sstp-server-read-how.aspx"&gt;this&lt;/a&gt; blog.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;Further References:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/tags/Troubleshooting/default.aspx"&gt;Troubleshooting articles @ RRAS blog site&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/947031"&gt;How to troubleshoot SSTP based connection failure in Windows&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Please send in your feedback via &lt;a href="http://blogs.technet.com/rrasblog/contact.aspx"&gt;email&lt;/a&gt;, in case we are missing some errors that you encounter most commonly in your deployment. &lt;/p&gt;  &lt;p&gt;Cheers,&lt;/p&gt;  &lt;p&gt;Dinesh Agarwal &lt;/p&gt;  &lt;p&gt;Amit Kumar (WINDOWS)&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights.]&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3272716" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Troubleshooting/">Troubleshooting</category></item><item><title>How to deploy RRAS based VPN server that gives dedicated IP to remote users/machines and allow them to access Internet using a dedicated public IP address</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/07/30/rras-as-vpn-server-providing-dedicated-ip-assigned-to-remote-vpn-clients.aspx</link><pubDate>Thu, 30 Jul 2009 17:21:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3269396</guid><dc:creator>rrasblog</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3269396</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/07/30/rras-as-vpn-server-providing-dedicated-ip-assigned-to-remote-vpn-clients.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In this blog, I will go through the steps to enable the following scenario:&lt;/p&gt;  &lt;p align="left"&gt;Let us say you have a bunch of remote application servers that should be exposed to Internet only after routing them via a central server (which does accounting/firewall etc). And as they are application servers, you will like to reserve a public IP address for each of them – so that their external name to public IP address mapping is maintained. &lt;/p&gt;  &lt;p&gt;How to enable this scenario?&lt;/p&gt;  &lt;p&gt;You can deploy Windows based RRAS server role as a VPN server plus a NAT router and configure it in such a way that a dedicated public IP address is allocated to each VPN clients (i.e. your application servers in this case). The way we will do this is: Enable NAT router functionality on the VPN server to redirect public IP addresses to private IP addresses using 1o1 mapping. Then enable VPN server to assign each VPN username a dedicated private IP address. And then create VPN client on the application server with different username.&lt;/p&gt;  &lt;p&gt;Let me walk you through the quick steps to do this:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Install Windows server on one of your edge machine at the central site. And connect it to Internet. &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Obtain a range of public IP addresses from the ISP – let us say IP1, IP2, IP3 .... IP10 - first one (i.e. IP1) by VPN server and rest nine (IP2 to IP9) for remote application servers that are exposed by this VPN server.&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;On this Windows server machine:      &lt;ul&gt;       &lt;li&gt;         &lt;div align="justify"&gt;Configure all the IP addresses given by ISP to Ethernet interface facing Internet (i.e. IP1 to IP10 in this example) – let us call this interface as “Internet Interface”.&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;Open “Server Manager” and install Routing and Remote Access server role. &lt;/li&gt;        &lt;li&gt;         &lt;div align="justify"&gt;Click on “Routing and Remote Access” MMC snap-in, configure RRAS as VPN server by following the steps 2.1 to 2.3 given in &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx"&gt;this&lt;/a&gt; blog – using “Internet Interface” as the public interface. &lt;b&gt;Note&lt;/b&gt;: Please ensure you have not selected “Enable security on the selected interface by setting up static packet filters” on the wizard. Because RRAS static filters and NAT doesn’t work together. &lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div align="justify"&gt;Now install the NAT component. On the MMC snap-in, select “IPv4” and “General”. Right click and select “New Routing Protocol” and select “NAT”. You will then see “NAT” node under IPv4.&amp;#160; &lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;      &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT0_2.png" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT0_2.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="NAT0" border="0" alt="NAT0" src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT0_thumb.png" width="366" height="242" mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT0_thumb.png" /&gt;&lt;/a&gt; &lt;/p&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div align="justify"&gt;Now configure the NAT component with a pool of public IP addresses. Right-click on NAT node and select the “Internet Interface”. Click OK. Select Interface Type as “Public Interface connected to the Internet” and select “Enable NAT on this interface”. &lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;      &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT1_4.png" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT1_4.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="NAT1" border="0" alt="NAT1" src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT1_thumb_1.png" width="248" height="267" mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT1_thumb_1.png" /&gt;&lt;/a&gt; &lt;/p&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div align="justify"&gt;Click on “Address Pool” tab at the top, click on “Add” and enter the range of IP addresses that you have allocated for your remote application servers (i.e. IP2 to IP10 in this example). Ensure you have entered the network mask correctly. Once done click OK. &lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;      &lt;p align="justify"&gt;&lt;a href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT2_2.png" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT2_2.png"&gt;&lt;img style="border-right-width: 0px; display: block; float: none; border-top-width: 0px; border-bottom-width: 0px; margin-left: auto; border-left-width: 0px; margin-right: auto" title="NAT2" border="0" alt="NAT2" src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT2_thumb.png" width="306" height="219" mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT2_thumb.png" /&gt;&lt;/a&gt; &lt;/p&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div align="justify"&gt;Now do a 1-to-1 mapping of each public IP address to a private IP address – that you will assign to your remote application servers when they establish VPN connection to this machine. Let us say the private IP addresses are – IPA, IPB, ... IPI. Click on “Reservations” button on “Address Pool” tab and add the reservation – e.g. public IP2 mapped to private IPA; public IP3 mapped to private IPB and so on.... Once done click OK.&lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;      &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT3_2.png" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT3_2.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="NAT3" border="0" alt="NAT3" src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT3_thumb.png" width="356" height="220" mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/NAT3_thumb.png" /&gt;&lt;/a&gt; &lt;/p&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div align="justify"&gt;The above step gets your NAT router mapping ready for one public IP address to one private IP address and vice-versa.&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div align="justify"&gt;Now configure the NAT component with VPN interface as the private interface. Right-click on NAT node and select the interface named “Internal” (this is the pseudo interface created by VPN server which is representing the interface on which all clients connect). Select Interface Type as “Private Interface connected to private network”.&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div align="justify"&gt;Now you need to configure the VPN server to ensure each remote application server when connects to this machine over VPN – gets a dedicated private IP address (one of IP address in IPA to IPI pool in this example) . This way after VPN connection, when these remote machine send packets to any machine beyond VPN server (say on Internet), their IP packets gets rightly translated – e.g. for appserverA – it is translated from IPA to IP2 when going out to Internet and vice versa when coming in from Internet.&lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;To enable this, click on “Users and Groups” snap-in (i.e. lusrmgr.msc) on the machine where the usernames are created with which each application server will establish a VPN connection. This can be a local machine OR the active directory machine (if RRAS server or its Radius server is joined to the domain). Open the snap-in, click on the username (e.g. appserverA), click on “Dial-in” tab, select “Network Access Permission” as “Allow access”, select “Assign Static IP Addresses” and then enter the static IPv4 address – i.e. private IP address assigned to this machine i.e. IPA. &lt;/p&gt;    &lt;p align="justify"&gt;&lt;a href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/lusr1_2.png" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/lusr1_2.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="lusr1" border="0" alt="lusr1" src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/lusr1_thumb.png" width="435" height="246" mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/RRASasVPNserverprovidingdedicatedIPassig_11733/lusr1_thumb.png" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p align="justify"&gt;Repeat the same step for all the other username for other application servers (e.g. appserverB to appserverI) – with different private IP addresses (i.e. IPB to IPI).&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div align="justify"&gt;Create VPN client connection on each of your application server machine – giving destination IP address of VPN server (i.e. IP1) and corresponding username (e.g. application server A using appserverA as the username).&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;Once the above steps are done – you are all set.&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;How does it work?&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div align="justify"&gt;Remote application servers working as VPN client connect to VPN server at the edge of your network.&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;The VPN client machine gets a private IP address assigned to them – e.g. application server A connecting with VPN username as appserverA gets IP address IPA.&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;When the machine sends an IP packet on Internet, the IP packet goes with inner IP header having source IP address as private IPA till the VPN server. When it reaches VPN server, it removes&amp;#160; the outer IP header, looks at inner IP header and does NAT translation to change the source IP address from private IPA to public IP2. And then send it on public Interface onto Internet.&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;The packet reaches the peer machine on internet. When the return IP packet traverses the Internet, the ISP forwards the packet to the VPN server machine.&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align="justify"&gt;VPN server receives the packet on Internet interface, looks at the NAT mapping and then changes destination IP address in IP header from public IP2 to private IPA. And then sees the private IPA is assigned to a VPN client. And it sends the packet on “Internal” interface which sends over VPN tunnel, adds outer IP header and the packet finally reaches the VPN client with destination IP address as IPA.&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Thanks to Aria Fahimipour from &lt;a href="http://www.ariaservers.com/" mce_href="http://www.ariaservers.com/"&gt;Aria servers&lt;/a&gt; for providing me the required details about this common usage scenario which has worked for them.&lt;/p&gt;  &lt;p&gt;Let me know if that works for you too.&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3269396" width="1" height="1"&gt;</description></item><item><title>How to configure Network Load Balancing (NLB) based cluster of VPN Servers</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/07/02/configuring-network-load-balancing-nlb-cluster-of-vpn-servers.aspx</link><pubDate>Thu, 02 Jul 2009 13:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3260727</guid><dc:creator>rrasblog</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3260727</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/07/02/configuring-network-load-balancing-nlb-cluster-of-vpn-servers.aspx#comments</comments><description>&lt;P&gt;Hello All, in this blog, I will discuss how to configure a "Network Load Balancing Cluster" of vpn servers to ensure high availability and scalability of vpn service. 
&lt;P&gt;For information about "Network Load Balancing (NLB)" feature in "Windows Server 2008 R2" please refer the following link: &lt;A href="http://technet.microsoft.com/en-us/library/cc725691.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc725691.aspx"&gt;http://technet.microsoft.com/en-us/library/cc725691.aspx&lt;/A&gt; 
&lt;P&gt;&lt;B&gt;How network load balancing cluster enhances scalability of vpn server?&lt;/B&gt; 
&lt;P&gt;To create a NLB VPN cluster each host runs Remote Access (VPN) Service &amp;amp; NLB Service. NLB allows all of the computers in the cluster to be addressed by the same cluster IP address. NLB distributes incoming client requests across the vpn servers in the cluster. The load weight to be handled by each vpn server can be configured as necessary. You can also add a vpn server dynamically to the cluster to handle increased load. In addition, NLB can direct all traffic to a designated single vpn server, which is called the default host. 
&lt;P&gt;&lt;B&gt;How network load balancing cluster ensures high availability of vpn server?&lt;/B&gt; 
&lt;P&gt;When a vpn server fails or goes offline, active connection to the failed or offline server are lost. But new connection request is automatically redistributed among the vpn servers that are still operating. However, if you bring a host down intentionally, you can use "drainstop" command to service all active connection prior to bringing the computer offline. Drainstop allows the host to continue surviving active connections but disables all new traffic to that host. 
&lt;P&gt;&lt;B&gt;How to configure a NLB cluster?&lt;/B&gt; 
&lt;P&gt;To configure the Network Load Balancing (NLB) cluster, you must configure three types of the parameters: 
&lt;UL&gt;
&lt;LI&gt;&lt;I&gt;Host parameters&lt;/I&gt;, which are specific to each host in a NLB cluster. 
&lt;LI&gt;&lt;I&gt;Cluster parameters&lt;/I&gt;, which apply to an NLB cluster as a whole. 
&lt;LI&gt;&lt;I&gt;Port rules&lt;/I&gt;, which control how the cluster functions. By default, a port rule equally balances all TCP/IP traffic across all servers. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;B&gt;In the following section we will describe step by step guide to deploy an nlb cluster of vpn servers for test lab.&lt;/B&gt; 
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;TABLE cellSpacing=0 cellPadding=0&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image001_2.gif" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image001_2.gif"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image001 border=0 alt=clip_image001 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image001_thumb.gif" width=640 height=410 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image001_thumb.gif"&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;
&lt;P&gt;&lt;B&gt;Verification step to make sure vpn server is configured properly before installing nlb:&lt;/B&gt; 
&lt;P&gt;1. Assign satic ip to vpn-server1 (say 201.0.0.1), vpn-server2 (say 201.0.0.2) [Note: NLB does not support DHCP. NLB disables DHCP on each interface that it configures, so the IP addresses must be static] 
&lt;P&gt;2. Ensure client is able to make vpn connection to both the servers for different tunnel types (PPTP, L2TP, SSTP or IKEv2). 
&lt;P&gt;&lt;B&gt;Install &amp;amp; Configure NLB in vpn-servers:&lt;/B&gt; 
&lt;P&gt;3. Install NLB in vpn-server1 &amp;amp; vpn-server2. 
&lt;P&gt;4. Create a new cluster using the NLB manager [Open nlbmgr.msc (in Administrative tools)] of vpn-server1 according the steps mentioned below. Add host to the cluster, choose priority of the host &amp;amp; assign cluster IP (say 201.0.0.11). 
&lt;P&gt;a) Add new host to the cluster: 
&lt;P&gt;Give host name or ip address and select the interface of the host for configuring cluster. 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image003_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image003_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image003 border=0 alt=clip_image003 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image003_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image003_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;b) Host parameter configuration: 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image005_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image005_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image005 border=0 alt=clip_image005 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image005_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image005_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;c) Configuring the cluster parameter 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image007_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image007_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image007 border=0 alt=clip_image007 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image007_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image007_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;Select cluster operation mode as unicast to specify that a unicast media access control (MAC) address should be used for cluster operation. In this mode, the MAC address of the cluster is assigned to the network adapter of the computer, and the built-in MAC address of the network adapter is not used. Unicast is the default setting for Cluster operation mode. 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image009_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image009_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image009 border=0 alt=clip_image009 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image009_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image009_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;d) Configuring Port Rules: 
&lt;P&gt;· Select &lt;B&gt;Affinity &lt;/B&gt;Single or Network to ensure that all network traffic from a particular client is directed to the same host. 
&lt;P&gt;· Select &lt;B&gt;Filtering mode &lt;/B&gt;to Multiple hosts or Single host considering the following: 
&lt;P&gt;o The &lt;B&gt;Multiple hosts&lt;/B&gt; parameter specifies that multiple hosts in the cluster will handle network traffic for the associated port rule. This filtering mode provides scaled performance and fault tolerance by distributing the network load among multiple hosts. You can specify that the load be equally distributed among the hosts or that each host will handle a specified load weight. 
&lt;P&gt;o The &lt;B&gt;Single host&lt;/B&gt; parameter specifies that network traffic for the associated port rule be handled by a single host in the cluster according to the specified handling priority. This filtering mode provides port specific fault tolerance for handling network traffic. 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image011_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image011_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image011 border=0 alt=clip_image011 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image011_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image011_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;5. Add vpn-server2 to the nlb cluster using nlb manager of the vpn-server1. (you can also do this step using the nlb manager of the vpn-server2 after "connecting to existing cluster" with cluster ip 201.0.0.11) 
&lt;P&gt;a) Add new host to the cluster 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image013_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image013_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image013 border=0 alt=clip_image013 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image013_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image013_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;b) Host parameter configuration 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image015_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image015_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image015 border=0 alt=clip_image015 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image015_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image015_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;c) Configuring Port Rules 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image017_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image017_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image017 border=0 alt=clip_image017 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image017_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image017_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;d) Configuring load weight for the host 
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image019_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image019_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image019 border=0 alt=clip_image019 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image019_thumb.jpg" width=644 height=483 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/ConfiguringNetworkLoadBalancingNLBCluste_EB0F/clip_image019_thumb.jpg"&gt;&lt;/A&gt; 
&lt;P&gt;6. Ensure both the server got same MAC Address for that interface &amp;amp; Cluster IP. [Note: NLB automatically instructs the driver that belongs to the cluster adapter to override the adapter's unique, built-in network address and to change its MAC address to the cluster's MAC address. This is the address used on all cluster hosts.] 
&lt;P&gt;&lt;B&gt;Verification after configuring nlb cluster for vpn server:&lt;/B&gt; 
&lt;P&gt;7. Make Connection from the client using Cluster IP. Connection should succeed &amp;amp; it should be connected to high priority server (vpn-sever1 in this case). 
&lt;P&gt;8. Give nlb drainstop on vpn-server1. 
&lt;P&gt;9. Drainstop allows the host to continue surviving active connections but disables all new traffic to that host. All new connections should go to vpn-server2. 
&lt;P&gt;10. Give nlb drainstop on the vpn-server2. 
&lt;P&gt;11. Now all new connections should fail since both the servers are in "drainstop" mode. 
&lt;P&gt;12. Give nlb start. 
&lt;P&gt;13. Client should be able to connect to vpn-server1. 
&lt;P&gt;With Regards, 
&lt;P&gt;Anupam Chakraborty (SDET, Windows Networking) &lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3260727" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Load+Balancing/">Load Balancing</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category></item><item><title>SSTP support on Forefront TMG server</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/06/10/sstp-support-on-isa-vpn-server.aspx</link><pubDate>Wed, 10 Jun 2009 14:36:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3252990</guid><dc:creator>rrasblog</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3252990</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/06/10/sstp-support-on-isa-vpn-server.aspx#comments</comments><description>&lt;P&gt;Hello Customers,&lt;/P&gt;
&lt;P&gt;If you are wondering, when will Forefront based VPN server be available on Windows server 2008 – specifically when will Forefront VPN server support SSTP – which is&amp;nbsp; the VPN tunnel that was added in Windows server 2008/Vista SP1 that provides ubiquitous VPN connectivity across firewalls/NAT using HTTPS. &lt;/P&gt;
&lt;P&gt;So here is the good news – Forefront team &lt;A href="http://blogs.technet.com/isablog/archive/2009/06/09/forefront-tmg-beta-3-is-released.aspx" mce_href="http://blogs.technet.com/isablog/archive/2009/06/09/forefront-tmg-beta-3-is-released.aspx"&gt;released Beta3 of new Forefront Threat Management Gateway (TMG)&lt;/A&gt;.&amp;nbsp; This release of TMG has bunch of features including SSTP integration i.e. TMG based VPN server will now support SSTP based VPN tunnels. Please check-it out, test it out and provide your valuable feedback to us.&lt;/P&gt;
&lt;P&gt;With Regards,&lt;/P&gt;
&lt;P&gt;Samir Jain&lt;/P&gt;
&lt;P&gt;Senior Program Manager&lt;/P&gt;
&lt;P&gt;Windows Networking&lt;/P&gt;
&lt;P&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3252990" width="1" height="1"&gt;</description></item><item><title>What type of certificate to install on the VPN server</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx</link><pubDate>Wed, 10 Jun 2009 13:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3252973</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3252973</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx#comments</comments><description>&lt;P&gt;Hello Friends,&lt;/P&gt;
&lt;P&gt;In my previous posting related to &lt;A href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx"&gt;VPN tunnel selection&lt;/A&gt;, I discussed various scenarios in which you need to install a certificate on the VPN server. To summarize this requirement in a nutshell: except PPTP tunnel, for all the other tunnel types (i.e. IKEv2, SSTP and L2TP/IPSec) VPN server machine should be installed with a &lt;EM&gt;valid&lt;/EM&gt; certificate. And what does &lt;EM&gt;valid &lt;/EM&gt;means is what I am going to discuss in this blog.&lt;/P&gt;
&lt;P&gt;Let us take a simple deployment scenario: You have one VPN server which is enabled for all VPN tunnels and is also used as NPS based Radius server – with EAP-TLS authentication. &lt;/P&gt;
&lt;P&gt;Here are the steps you need to follow:&lt;/P&gt;
&lt;P&gt;1) Install a certificate inside &lt;EM&gt;machine store&lt;/EM&gt; (i.e. Local Computer certificate store) of the VPN server. The key properties that you MUST ensure are set inside the machine certificate includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Common name (CN):&lt;/STRONG&gt; Same as the hostname OR IPv4/v6 address that is configured as VPN destination on the VPN client. i.e. if the VPN client is configured with the hostname, then set this as same hostname OR if the VPN client is configured with the IP address, then set this as same IP address. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Extended Key Usage (EKU)&lt;/STRONG&gt;:&amp;nbsp; Select “Server Authentication” and “IP Security IKE intermediate”. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Key Usage: &lt;/STRONG&gt;Select Digital signature and Key encipherment. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;This certificate must be requested from the certificate authority (CA) – who trust chain is installed on the VPN client machine (see next step on special care if you are using public CA). The certificate can be requested from the CA using any mechanism that supports requesting above set of properties. For example, if you are using Active Directory Certificate Services – you can request a certificate by creating a “Custom request” by clicking on relevant certificate store inside Certificate Manager (certmgr.msc). And you can then submit the certificate request to the CA. And once the request is approved, you can install the machine certificate on the VPN Server.&lt;/P&gt;
&lt;P&gt;2) Once the certificate is installed on the VPN server, you must configure the VPN server appropriately to point to the relevant machine certificate:&lt;/P&gt;
&lt;P&gt;For &lt;U&gt;SSTP&lt;/U&gt;: Ensure the SSTP tunnel is configured for this certificate. For Windows 2008 R2 – RRAS server has a UI/netsh way of selecting the certificate that will be used by SSTP – which is blogged &lt;A href="http://blogs.technet.com/rrasblog/archive/2009/02/11/sstp-certificate-selection.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/02/11/sstp-certificate-selection.aspx"&gt;here&lt;/A&gt;. For Windows 2008, there is a regkey driven way of ensuring the same which is blogged &lt;A href="http://blogs.technet.com/rrasblog/archive/2007/11/08/do-you-want-to-change-the-certificate-used-by-the-sstp-server-read-how.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2007/11/08/do-you-want-to-change-the-certificate-used-by-the-sstp-server-read-how.aspx"&gt;here&lt;/A&gt; and &lt;A href="http://blogs.technet.com/rrasblog/archive/2007/10/04/how-to-change-the-machine-certificate-of-sstp-based-rras-server.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2007/10/04/how-to-change-the-machine-certificate-of-sstp-based-rras-server.aspx"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For &lt;U&gt;L2TP/IPSec&lt;/U&gt;: No other configuration is required&lt;/P&gt;
&lt;P&gt;For &lt;U&gt;IKEv2 EAP authentication&lt;/U&gt;: No other configuration is required&lt;/P&gt;
&lt;P&gt;For &lt;U&gt;IKEv2 machine certificate authentication&lt;/U&gt;: Ensure the trusted root certificate store on the VPN Server contains **&lt;STRONG&gt;only&lt;/STRONG&gt;** the trust root certificate that matches the trust chain with which the client will send the machine certificate. And you MUST delete all the other trust chain on the VPN Server – to avoid any malicious client machine having a certificate with one of those trust chain to be able to successfully connect to this VPN server using IKEv2 machine certificate authentication. &lt;STRONG&gt;&lt;FONT color=#ff0000&gt;WARNING&lt;/FONT&gt;&lt;/STRONG&gt;: If you have enabled IKEv2 machine certificate authentication scenario, you MUST NOT install any trusted root certificates from a public certificate authority (e.g. Verisign) on the VPN server machine. Otherwise, any malicious user&amp;nbsp; with a machine certificate from that particular public CA – can connect with your VPN server. You must only install the trusted root certificate of your own certificate authority.&lt;/P&gt;
&lt;P&gt;Hope this posting helps you select the right certificate&lt;/P&gt;
&lt;P&gt;For further details about the certificates, please refer to &lt;A href="https://www.carbonwind.net/blog/post/2009/05/30/VPN-Reconnect-in-Windows-7-RC-redux.aspx" mce_href="https://www.carbonwind.net/blog/post/2009/05/30/VPN-Reconnect-in-Windows-7-RC-redux.aspx"&gt;this&lt;/A&gt; excellent blog by Adrian.&lt;/P&gt;
&lt;P&gt;With Regards,&lt;/P&gt;
&lt;P&gt;Samir Jain&lt;/P&gt;
&lt;P&gt;Senior Program Manager&lt;/P&gt;
&lt;P&gt;Windows Networking&lt;/P&gt;
&lt;P&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3252973" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Troubleshooting/">Troubleshooting</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>How to configure RRAS based SSTP VPN server behind F5 BIGIP SSL load balancer</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/05/26/configuring-rras-based-sstp-vpn-server-behind-f5-bigip-ssl-load-balancer.aspx</link><pubDate>Tue, 26 May 2009 12:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3245643</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3245643</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/05/26/configuring-rras-based-sstp-vpn-server-behind-f5-bigip-ssl-load-balancer.aspx#comments</comments><description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;In this blog, I will discuss how to load balance SSTP based VPN servers using a F5 BIGIP SSL load balancer. &lt;/P&gt;
&lt;P&gt;Lets look at the deployment scenario first: You are having a pool of RRAS based VPN servers hosted behind F5 BIGIP load balancer. The F5 BIGIP load balancer terminates the HTTPS connections coming in from different SSTP based VPN clients, load balances the same by sending HTTP connections to one of the VPN server from this&amp;nbsp; pool of RRAS based VPN servers.&lt;/P&gt;
&lt;P&gt;I will walk-through a sample lab set-up, however you can modify the same according to your own deployment.&lt;/P&gt;
&lt;P align=center&gt;&lt;STRONG&gt;Configuring F5 BIGIP&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Connect to F5 BIGIP management console web interface. Go to Local Traffic &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;SSL Certificates: &lt;/STRONG&gt;Import the SSL certificate that will be used during HTTPS negotiation. Please note: the subject name (CN) of the certificate should be same as the VPN destination name as configured inside VPN client. This can be either hostname or IP address – depending upon the VPN client configuration. Also note: The thumbprint of this certificate will be configured inside RRAS server (under Sha1CertificateHash and Sha256CertificateHash registry keys as given in step 3 under &lt;STRONG&gt;Configuring RRAS as SSTP VPN server&lt;/STRONG&gt;). &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Profiles: &lt;/STRONG&gt;Create two profiles: a) Name: &lt;EM&gt;SSTP_Http&lt;/EM&gt; profile derived from the existing parent template `HTTP’.&amp;nbsp; This profile will be attached to the virtual server so that we can add an iRule to do HTTP filtering based on SSTP URI. b) Name: &lt;EM&gt;SSTP_Client&lt;/EM&gt; profile derived from the existing parent template `ClientSSL’. This will be configured with the certificate imported in step 2 and will be used to terminate the HTTPS connections coming in from the client side. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Nodes: &lt;/STRONG&gt;Create nodes specifying IP address of each of the VPN servers (i.e. RRAS server’s IP address facing towards BIGIP or Internet). &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pools&lt;/STRONG&gt;: Create a pool with name &lt;EM&gt;SSTP-Pool&lt;/EM&gt; that contains the node we created in step 4. Enter the name of the pool, add gateway_icmp health monitor, select the nodes and select the service port as 80 or any other value that is configured on SSTP based VPN server&amp;nbsp; to listen for incoming HTTP connections. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;iRules:&lt;/STRONG&gt;&amp;nbsp; &lt;EM&gt;This is the best part of F5 BIGIP&lt;/EM&gt; – without doing any firmware code change, we were able to get SSTP VPN server getting load balanced – by creating&amp;nbsp; a new iRule with name: &lt;EM&gt;SSTP_iRule &lt;/EM&gt;as given in the end of this article. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Virtual Server: &lt;/STRONG&gt;Create a new Virtual server – name: &lt;EM&gt;SSTP_VirtualServer&lt;/EM&gt;. Specify the destination IP address, service port as 443 (HTTPS), configuration as `Basic’. For HTTP profile – select &lt;EM&gt;SSTP_Http&lt;/EM&gt; and SSL client profile – select &lt;EM&gt;SSTP_Client&lt;/EM&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Resources: &lt;/STRONG&gt;Add the iRule created in step 6 – i.e. &lt;EM&gt;SSTP_iRule&lt;/EM&gt; to the virtual server. &lt;/LI&gt;&lt;/OL&gt;
&lt;P align=center&gt;&lt;STRONG&gt;Configuring RRAS as SSTP VPN server&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;On WS 2008 or later OS, using Server Manager, install RRAS server role inside “Network Policy and Access server” node. &lt;/LI&gt;
&lt;LI&gt;Once installed, configure RRAS server as VPN server – using RRAS configuration wizard (details given in SSTP step-by-step guide -&amp;nbsp; in references). &lt;/LI&gt;
&lt;LI&gt;By default SSTP based VPN server is configured to listen for HTTPS connections coming in from VPN clients – however in this scenario it is required to be configured for accepting HTTP connections. To configure RRAS VPN server to listen for HTTP connections, configure &lt;EM&gt;UseHTTPS, ListenerPort, Sha1CertificateHash and Sha256CertificateHash &lt;/EM&gt;registry keys (details given in KB947030 and KB947054). Basically – you need to specify UseHTTPS as 0 (i.e. listen for HTTP connections), ListenerPort as 80 or some other value on which you will like to listen on HTTP connections (&lt;EM&gt;the same MUST be set inside F5 pool), &lt;/EM&gt;Sha1CertificateHash and Sha256CertificateHash with the thumbprint of the certificate installed on F5 BIGIP (which will be sent to the client during HTTPS connection establishment phase). &lt;/LI&gt;
&lt;LI&gt;Once you have set the regkeys, restart RRAS server. &lt;/LI&gt;
&lt;LI&gt;Follow the same steps on all the RRAS servers hosted behind F5 BIGIP (i.e. for all the nodes created on BIGIP). &lt;/LI&gt;
&lt;LI&gt;And you are all set-to-go and test the stuff. &lt;/LI&gt;&lt;/OL&gt;
&lt;P align=center&gt;&lt;STRONG&gt;Testing&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;DIV align=left&gt;Create a SSTP VPN client on Vista SP1 or later OS – give the destination name as the name/IP address of F5 BIGIP virtual server. Note: This must be same as the subject name of SSL certificate installed on the F5 BIGIP SSL certificate.&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV align=left&gt;Install the trusted root certificate on the client machine&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV align=left&gt;Click connect. The HTTPS connection must go through F5 BIGIP virtual server terminating HTTPS connection and redirecting HTTP connection to one of the RRAS server. &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV align=left&gt;For further troubleshooting, look at F5 logs and RRAS event logs.&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;References&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="http://download.microsoft.com/download/b/1/0/b106fc39-936c-4857-a6ea-3fb9d1f37063/Deploying%20SSTP%20Remote%20Access%20Step%20by%20Step%20Guide.doc" mce_href="http://download.microsoft.com/download/b/1/0/b106fc39-936c-4857-a6ea-3fb9d1f37063/Deploying%20SSTP%20Remote%20Access%20Step%20by%20Step%20Guide.doc"&gt;Step-by-step guide: Deploying SSTP Remote Access&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/kb/947030" mce_href="http://support.microsoft.com/kb/947030"&gt;KB947030: How to deploy SSTP based VPN server behind SSL load balancer&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/kb/947054" mce_href="http://support.microsoft.com/kb/947054"&gt;KB947054: Registry entries that RRAS adds in WS08&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;Here is the &lt;STRONG&gt;iRule&lt;/STRONG&gt; with name &lt;EM&gt;SSTP_iRule &lt;/EM&gt;that must be created on F5 BIGIP to redirect SSTP client connections to a pool of VPN servers: &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;################################## &lt;/P&gt;
&lt;P&gt;when HTTP_REQUEST { &lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;log local0. "HTTP Method: [HTTP::method]"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;log local0. "HTTP URI: [HTTP::uri]"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;log local0. "HTTP Host: [HTTP::host]"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;log local0. "Content Length: [HTTP::header Content-Length]"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;if { ([HTTP::method] eq "SSTP_DUPLEX_POST") and&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;([HTTP::uri] eq "/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/") } {&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;log local0. "Found SSTP Request, routing to sstp_servers pool"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;pool SSTP-Pool&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;# disable the HTTP profile for the rest of the connection&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;HTTP::disable&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;} else {&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;log local0. "Non SSTP Request, dropping connection. You can change it according to your use"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;drop&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;}&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;} &lt;/P&gt;
&lt;P&gt;##################################&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Samir Jain&lt;/P&gt;
&lt;P&gt;Senior Program Manager&lt;/P&gt;
&lt;P&gt;Windows Networking&lt;/P&gt;
&lt;P&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3245643" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/SSTP/">SSTP</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category></item><item><title>Windows7 PPPoE or VPN connectivity experience – we would like to hear back from you</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/05/13/windows7-pppoe-or-vpn-connectivity-experience-we-would-like-to-hear-back-from-you.aspx</link><pubDate>Wed, 13 May 2009 14:22:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3240218</guid><dc:creator>rrasblog</dc:creator><slash:comments>8</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3240218</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/05/13/windows7-pppoe-or-vpn-connectivity-experience-we-would-like-to-hear-back-from-you.aspx#comments</comments><description>&lt;p&gt;Hello Friends,&lt;/p&gt;  &lt;p&gt;As you know – Windows7 RC is out and we will like to hear back from you !&lt;/p&gt;  &lt;p&gt;In Windows7, we did couple of changes on the remote access client that includes dialup, broadband (aka PPPoE) and VPN scenarios. Windows7 brings in simpler connectivity experience inside View Available Networks (VAN) that is shown in networking system tray icon. &lt;/p&gt;  &lt;p&gt;In Windows7 beta release, we heard from you on some PPPoE connectivity issues in certain regions and some PPPoE performance issues. We actively listened to your valuable feedback and quickly acted on it. We have fixed all of those issues in Windows7 RC release. &lt;/p&gt;  &lt;p&gt;If you are using Windows7 RC build and still facing any connectivity or performance issues in&amp;#160; dialup, PPPoE or VPN area, please get back to us by sending us an email (click on the &lt;a href="http://blogs.technet.com/rrasblog/contact.aspx"&gt;Email&lt;/a&gt; link above).&lt;/p&gt;  &lt;p&gt;We sincerely appreciate your feedback. &lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3240218" width="1" height="1"&gt;</description></item><item><title>Enhancements to VPN Reconnect in W7 RC</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/05/11/enhancements-to-vpn-reconnect-in-w7-rc.aspx</link><pubDate>Mon, 11 May 2009 16:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3238840</guid><dc:creator>rrasblog</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3238840</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/05/11/enhancements-to-vpn-reconnect-in-w7-rc.aspx#comments</comments><description>&lt;P&gt;Hello Folks,&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;By now all of you must have heard about the formal release of W7 RC. In case you don’t have it already here is the link from where you can download the RC bits&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://www.microsoft.com/windows/windows-7/default.aspx" mce_href="http://www.microsoft.com/windows/windows-7/default.aspx"&gt;&lt;SPAN style="COLOR: windowtext"&gt;&lt;FONT size=3 face=Calibri&gt;http://www.microsoft.com/windows/windows-7/default.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In RC the RAS team has made some enhancements to the VPN Reconnect feature. Here are the details of the change and some recommendations on deployment. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Change in method used to calculate MSK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Details of Enhancement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In accordance with the IKEv2 RFC, in EAP &amp;nbsp;authentication, the shared secret generated is used by the IKEv2 connection initiator and responder to generate AUTH payloads &amp;nbsp;for EAP (see section 2.16 in RFC 4306 for more details). This shared secret is called the MSK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3 face=Calibri&gt;In W7 RC we have changed the method used to calculate the MSK for EAP-MSCHAPv2 . The new method has been documented on MSDN and can be found at &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx"&gt;&lt;FONT size=3 face=Calibri&gt;http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Impact&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The MSK calculation method used in RC is different from that in Beta and implementation of the new method involved changes on both the client and server. Hence RC build is required on both client and server to successfully setup an IKEv2 connection using EAP-MSCHAPv2 authentication. IKEv2 connections between Beta client and RC server and vice versa will fail if EAP-MSCHAPv2 authentication is used &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Vendors implementing EAP-MACHAPv2 for IKEv2 MUST derive the MSK as specified in &lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx"&gt;http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-weight: bold"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Validation of VPN server machine certificate by client for better security&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Details of Enhancement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;We have made a change to IKEv2 on the client side to start validating the machine certificate sent by the VPN server that it is connecting to. This change helps prevent possible MITM and dictionary attacks thereby strengthening IKEv2 security. It is not possible to disable these checks on the client&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 35.45pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Deployment Recommendation&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 2cm; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Certificate installed on the server should have the following values for certain important fields in the certificate. Corresponding root certificates should be installed on the client&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Certificate Name (CN): This field should contain the name or IP address of the server (depending on which one is being used by the client) that is&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; being validated by the client. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;EKU: Should be a ‘Server Authentication’ certificate. If there are multiple certificates present in the machine store of the server then additionally &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; specifying ‘&lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'MS Shell Dlg 2','sans-serif'; FONT-SIZE: 10pt; mso-ansi-language: EN-US" lang=EN-US&gt;IP security IKE intermediate’ (OID: 1.3.6.1.5.5.8.2.2)&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt; in the EKU of the cert will ensure that the cert is picked over other certificates in the &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; store. The latter is &lt;B&gt;highly recommended&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 2cm; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;If you are running SSTP already in your setup then the same server machine certificate can be used for both SSTP and IKEv2 but the certificate should satisfy the criteria mentioned above. Since root certs required for SSTP are already present on the client no client side changes are needed in this case&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Impact/Troubleshooting Tips&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-IN; mso-bidi-language: AR-SA"&gt;If right certificate is not configured on IKEv2 server or if correct trusted root certificate is not present on the client then IKEv2 connections might fail. Error code seen &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-IN; mso-bidi-language: AR-SA"&gt;is 13801 which indicates that validation of the server certificate is failing. If multi-tunnel VPN strategy is used, then a fall back to the next tunnel will happen and the &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-IN; mso-bidi-language: AR-SA"&gt;VPN connection will go through. For e.g. for ‘Automatic’ tunnel type fall back will happen to SSTP&lt;/SPAN&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3238840" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/IKEv2/">IKEv2</category></item><item><title>3rd party VPN client compatibility with Windows 7 and Windows Server 2008 R2</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/05/05/vpn-client-compatibility-with-windows-7-and-windows-server-2008-r2.aspx</link><pubDate>Tue, 05 May 2009 14:39:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3235576</guid><dc:creator>rrasblog</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3235576</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/05/05/vpn-client-compatibility-with-windows-7-and-windows-server-2008-r2.aspx#comments</comments><description>&lt;META name=ProgId content=Word.Document&gt;
&lt;META name=Generator content="Microsoft Word 12"&gt;
&lt;META name=Originator content="Microsoft Word 12"&gt;&lt;LINK rel=File-List href="file:///C:%5CUsers%5CASHISH%7E1.FAR%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml" mce_href="file:///C:%5CUsers%5CASHISH%7E1.FAR%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;LINK rel=themeData href="file:///C:%5CUsers%5CASHISH%7E1.FAR%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx" mce_href="file:///C:%5CUsers%5CASHISH%7E1.FAR%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;LINK rel=colorSchemeMapping href="file:///C:%5CUsers%5CASHISH%7E1.FAR%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml" mce_href="file:///C:%5CUsers%5CASHISH%7E1.FAR%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;
&lt;STYLE&gt;
&lt;!--
 /* Font Definitions */
 @font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;
	mso-font-alt:宋体;
	mso-font-charset:134;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:3 680460288 22 0 262145 0;}
@font-face
	{font-family:PMingLiU;
	panose-1:2 2 5 0 0 0 0 0 0 0;
	mso-font-alt:新細明體;
	mso-font-charset:136;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-1610611969 684719354 22 0 1048577 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1107304683 0 0 415 0;}
@font-face
	{font-family:"\@PMingLiU";
	panose-1:2 2 5 0 0 0 0 0 0 0;
	mso-font-charset:136;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-1610611969 684719354 22 0 1048577 0;}
@font-face
	{font-family:"\@SimSun";
	panose-1:2 1 6 0 3 1 1 1 1 1;
	mso-font-charset:134;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:3 680460288 22 0 262145 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-name:"Normal\,Text\,t";
	mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:0in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
h1
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-link:"Heading 1 Char";
	mso-style-next:"Normal\,Text\,t";
	margin-top:24.0pt;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:0in;
	margin-bottom:.0001pt;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan lines-together;
	page-break-after:avoid;
	mso-outline-level:1;
	font-size:14.0pt;
	font-family:"Cambria","serif";
	mso-ascii-font-family:Cambria;
	mso-ascii-theme-font:major-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:major-fareast;
	mso-hansi-font-family:Cambria;
	mso-hansi-theme-font:major-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:major-bidi;
	color:#365F91;
	mso-themecolor:accent1;
	mso-themeshade:191;
	mso-font-kerning:12.0pt;}
h2
	{mso-style-name:"Heading 2\,h2";
	mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"Heading 1";
	mso-style-link:"Heading 2 Char";
	mso-style-next:"Normal\,Text\,t";
	margin-top:.25in;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	page-break-after:avoid;
	mso-outline-level:2;
	font-size:18.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;
	mso-bidi-font-weight:normal;}
p.MsoHeader, li.MsoHeader, div.MsoHeader
	{mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-link:"Header Char";
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	tab-stops:center 3.25in right 6.5in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.MsoFooter, li.MsoFooter, div.MsoFooter
	{mso-style-name:"Footer\,f";
	mso-style-unhide:no;
	mso-style-parent:Header;
	mso-style-link:"Footer Char";
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:12.0pt;
	margin-left:0in;
	text-align:right;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:PMingLiU;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.MsoListBullet, li.MsoListBullet, div.MsoListBullet
	{mso-style-noshow:yes;
	mso-style-priority:99;
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:.25in;
	mso-add-space:auto;
	text-indent:-.25in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	mso-list:l0 level1 lfo1;
	tab-stops:list .25in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.MsoListBulletCxSpFirst, li.MsoListBulletCxSpFirst, div.MsoListBulletCxSpFirst
	{mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-type:export-only;
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.25in;
	margin-bottom:.0001pt;
	mso-add-space:auto;
	text-indent:-.25in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	mso-list:l0 level1 lfo1;
	tab-stops:list .25in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.MsoListBulletCxSpMiddle, li.MsoListBulletCxSpMiddle, div.MsoListBulletCxSpMiddle
	{mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.25in;
	margin-bottom:.0001pt;
	mso-add-space:auto;
	text-indent:-.25in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	mso-list:l0 level1 lfo1;
	tab-stops:list .25in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.MsoListBulletCxSpLast, li.MsoListBulletCxSpLast, div.MsoListBulletCxSpLast
	{mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:.25in;
	mso-add-space:auto;
	text-indent:-.25in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	mso-list:l0 level1 lfo1;
	tab-stops:list .25in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	mso-style-unhide:no;
	mso-ansi-font-size:10.0pt;
	mso-bidi-font-size:9.0pt;
	color:blue;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-noshow:yes;
	mso-style-priority:99;
	color:purple;
	mso-themecolor:followedhyperlink;
	text-decoration:underline;
	text-underline:single;}
span.Heading2Char
	{mso-style-name:"Heading 2 Char";
	mso-style-unhide:no;
	mso-style-locked:yes;
	mso-style-link:"Heading 2\,h2";
	mso-ansi-font-size:18.0pt;
	mso-bidi-font-size:18.0pt;
	font-family:"Arial","sans-serif";
	mso-ascii-font-family:Arial;
	mso-fareast-font-family:SimSun;
	mso-hansi-font-family:Arial;
	mso-font-kerning:12.0pt;
	font-weight:bold;
	mso-bidi-font-weight:normal;}
span.LabelEmbedded
	{mso-style-name:"Label Embedded\,le";
	mso-style-unhide:no;
	mso-bidi-font-size:9.0pt;
	font-weight:bold;
	mso-bidi-font-weight:normal;}
p.TableSpacing, li.TableSpacing, div.TableSpacing
	{mso-style-name:"Table Spacing\,ts";
	mso-style-unhide:no;
	mso-style-next:"Normal\,Text\,t";
	margin-top:4.0pt;
	margin-right:0in;
	margin-bottom:4.0pt;
	margin-left:0in;
	mso-pagination:widow-orphan;
	font-size:4.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.AlertLabel, li.AlertLabel, div.AlertLabel
	{mso-style-name:"Alert Label\,al";
	mso-style-unhide:no;
	margin-top:6.0pt;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:0in;
	margin-bottom:.0001pt;
	line-height:15.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	page-break-after:avoid;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;
	font-weight:bold;
	mso-bidi-font-weight:normal;}
span.FooterChar
	{mso-style-name:"Footer Char";
	mso-style-unhide:no;
	mso-style-locked:yes;
	mso-style-link:"Footer\,f";
	font-family:"Arial","sans-serif";
	mso-ascii-font-family:Arial;
	mso-fareast-font-family:PMingLiU;
	mso-hansi-font-family:Arial;
	mso-font-kerning:12.0pt;}
p.BulletedList1, li.BulletedList1, div.BulletedList1
	{mso-style-name:"Bulleted List 1\,bl1";
	mso-style-unhide:no;
	mso-style-parent:"List Bullet";
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:.25in;
	text-indent:-.25in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	mso-list:l0 level1 lfo1;
	tab-stops:list .25in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.BulletedList2, li.BulletedList2, div.BulletedList2
	{mso-style-name:"Bulleted List 2\,bl2";
	mso-style-unhide:no;
	mso-style-parent:"List Bullet";
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:.5in;
	text-indent:-.25in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	mso-list:l1 level1 lfo2;
	tab-stops:list .5in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.PageHeader, li.PageHeader, div.PageHeader
	{mso-style-name:"Page Header\,pgh";
	mso-style-unhide:no;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:12.0pt;
	margin-left:0in;
	text-align:right;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;
	font-weight:bold;
	mso-bidi-font-weight:normal;}
p.PageFooter, li.PageFooter, div.PageFooter
	{mso-style-name:"Page Footer\,pgf";
	mso-style-unhide:no;
	margin:0in;
	margin-bottom:.0001pt;
	text-align:right;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
p.AlertTextBulletedList2, li.AlertTextBulletedList2, div.AlertTextBulletedList2
	{mso-style-name:"Alert Text Bulleted List 2\,atbl2";
	mso-style-unhide:no;
	mso-style-parent:"Bulleted List 2\,bl2";
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:.5in;
	text-indent:-.25in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;
	mso-pagination:widow-orphan;
	mso-list:l1 level1 lfo2;
	tab-stops:list .5in;
	font-size:10.0pt;
	font-family:"Arial","sans-serif";
	mso-fareast-font-family:SimSun;
	mso-bidi-font-family:"Times New Roman";
	mso-font-kerning:12.0pt;}
span.Heading1Char
	{mso-style-name:"Heading 1 Char";
	mso-style-unhide:no;
	mso-style-locked:yes;
	mso-style-link:"Heading 1";
	mso-ansi-font-size:14.0pt;
	mso-bidi-font-size:14.0pt;
	font-family:"Cambria","serif";
	mso-ascii-font-family:Cambria;
	mso-ascii-theme-font:major-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:major-fareast;
	mso-hansi-font-family:Cambria;
	mso-hansi-theme-font:major-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:major-bidi;
	color:#365F91;
	mso-themecolor:accent1;
	mso-themeshade:191;
	mso-font-kerning:12.0pt;
	font-weight:bold;}
span.HeaderChar
	{mso-style-name:"Header Char";
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-unhide:no;
	mso-style-locked:yes;
	mso-style-link:Header;
	font-family:"Arial","sans-serif";
	mso-ascii-font-family:Arial;
	mso-fareast-font-family:SimSun;
	mso-hansi-font-family:Arial;
	mso-font-kerning:12.0pt;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	font-size:10.0pt;
	mso-ansi-font-size:10.0pt;
	mso-bidi-font-size:10.0pt;}
.MsoPapDefault
	{mso-style-type:export-only;
	margin-top:3.0pt;
	margin-right:0in;
	margin-bottom:3.0pt;
	margin-left:0in;
	line-height:14.0pt;
	mso-line-height-rule:exactly;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;
	mso-header-margin:1.0in;
	mso-footer-margin:1.0in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:1161654485;
	mso-list-type:simple;
	mso-list-template-ids:-1047741128;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-style-link:"Bulleted List 1";
	mso-level-text:;
	mso-level-tab-stop:.25in;
	mso-level-number-position:left;
	margin-left:.25in;
	text-indent:-.25in;
	font-family:Symbol;}
@list l1
	{mso-list-id:1892156636;
	mso-list-type:simple;
	mso-list-template-ids:236997216;}
@list l1:level1
	{mso-level-number-format:bullet;
	mso-level-style-link:"Bulleted List 2";
	mso-level-text:;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--&gt;
&lt;/STYLE&gt;

&lt;P class=MsoNormal&gt;When you upgrade your computer from an older version of Windows to Windows®&amp;nbsp;7 or Windows Server®&amp;nbsp;2008&amp;nbsp;R2, your 3rd-party virtual private network (VPN) client programs might not work. As Windows evolves, sometimes changes to the underlying infrastructure are required to implement new features, and these changes can sometime break compatibility with older programs. While Microsoft makes every effort to maintain compatibility with older programs, there are some categories of programs that are more likely to be impacted by these changes. VPN clients are one of them. &lt;/P&gt;
&lt;P class=MsoNormal&gt;The tables below show the VPN clients available from different vendors. The tables include the minimum version number that has been tested and known to be compatible with Windows&amp;nbsp;7 and a link to the vendor’s Web site where you can download the client.&lt;/P&gt;
&lt;P class=MsoNormal&gt;Be sure to review the &lt;SPAN class=LabelEmbedded&gt;More information&lt;/SPAN&gt; column for any important notes that might be relevant to your use of the client.&lt;/P&gt;
&lt;P class=AlertLabel&gt;Notes &lt;/P&gt;
&lt;P class=AlertTextBulletedList2&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.&lt;/P&gt;
&lt;P class=AlertTextBulletedList2&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, about the performance or reliability of these products. &lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z1" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z1"&gt;AT&amp;amp;T&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z2" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z2"&gt;Checkpoint&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z3" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z3"&gt;CISCO&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z4" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z4"&gt;Citrix&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z5" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z5"&gt;F5&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z6" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z6"&gt;Juniper&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z7" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z7"&gt;NCP&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z8" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z8"&gt;NetGear&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z9" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z9"&gt;Nortel&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z10" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z10"&gt;SafeNet&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z11" mce_href="http://blogs.technet.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=4334&amp;amp;postid=3235576#z11"&gt;Sonic Wall&lt;/A&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;&lt;B&gt;Ashish Jain&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=BulletedList1&gt;Program Manager&lt;/P&gt;
&lt;P class=BulletedList1&gt;Routing and Remote Access&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087528 name=_Toc228087528&gt;&lt;/A&gt;&lt;A title=z1 name=z1&gt;&lt;/A&gt;&lt;SPAN&gt;AT&amp;amp;T&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 40.3pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=54&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.95pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 94.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=126&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 40.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=54&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPsec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;V7.6.2&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.95pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.attnetclient.com/v7/download.php" mce_href="http://www.attnetclient.com/v7/download.php"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 94.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=126&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Found heap corruption issue in the VPN client. Not a blocking issue, and was present on Windows Vista. AT&amp;amp;T working on resolving the issue.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087529 name=_Toc228087529&gt;&lt;/A&gt;&lt;A title=z2 name=z2&gt;&lt;/A&gt;&lt;SPAN&gt;Checkpoint&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 53.8pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 135pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=180&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 152.45pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=203&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 53.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPsec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;NGX R60 HFA2&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 135pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=180&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: April 2007&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://updates.checkpoint.com/fileserver/ID/7951/FILE/SC_NGX_R60_HFA2_630000044.msi" mce_href="http://updates.checkpoint.com/fileserver/ID/7951/FILE/SC_NGX_R60_HFA2_630000044.msi"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 152.45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=203&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Clean installation working with limited testing.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 53.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SNX R66 HFA 01&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 135pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=180&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: June 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=8726" mce_href="https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=8726"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 152.45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=203&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL Network Extender: Clean installation working with limited testing. Upgrade scenario has been flagged for upgrade block.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.checkpoint.com/products/ssl_network_ext/index.html" mce_href="http://www.checkpoint.com/products/ssl_network_ext/index.html"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 53.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Endpoint Connect&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;NGX R66&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 135pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=180&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: June 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=8729" mce_href="https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=8729"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 152.45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=203&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Clean installation working with limited testing.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 53.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Endpoint Connect&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;NGX R66&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 135pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=180&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: June 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.checkpoint.com/downloads/quicklinks/downloads_sr.html" mce_href="http://www.checkpoint.com/downloads/quicklinks/downloads_sr.html"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 152.45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=203&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Clean installation working with limited testing.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087530 name=_Toc228087530&gt;&lt;/A&gt;&lt;A title=z3 name=z3&gt;&lt;/A&gt;&lt;SPAN&gt;CISCO&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN Client&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 48.9pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=65&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45.35pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 41.6pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=55&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 102.65pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=137&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.75in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=168&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 Build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Cisco AnyConnect VPN Client (SSL VPN)&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 48.9pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=65&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;2.3.x&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 41.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=55&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;2.3.x&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 102.65pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=137&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml" mce_href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=168&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;You must have a Cisco.com user account to download.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7048&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Cisco AnyConnect VPN Client (SSL VPN)&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 48.9pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=65&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;2.3.x&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 41.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=55&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;2.3.x&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 102.65pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=137&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml" mce_href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=168&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;You must have a Cisco.com user account to download.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7048&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Cisco VPN Client (IPsec)&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 48.9pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=65&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;X86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 41.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=55&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;5.0.5+&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 102.65pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=137&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml" mce_href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=168&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Cisco VPN Client (IPsec)&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 48.9pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=65&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;5.0.5+&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 41.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=55&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;5.0.5+&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 102.65pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=137&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml" mce_href="http://www.cisco.com/kobayashi/sw-center/sw-vpn.shtml"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=168&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;No official support for this version planned by Cisco. Use the Cisco AnyConnect VPN Client for both Windows 7 and x64 support&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7048&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087531 name=_Toc228087531&gt;&lt;/A&gt;&lt;A title=z4 name=z4&gt;&lt;/A&gt;&lt;SPAN&gt;Citrix&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Date&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 76.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=102&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 78.7pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=105&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 82.75pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=110&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Access Gateway Standard Edition 4.5.8&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Available now&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 76.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=102&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.citrix.com/site/SS/downloads/results.asp?productID=15005" mce_href="http://www.citrix.com/site/SS/downloads/results.asp?productID=15005"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 78.7pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=105&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;VPN client must be re-installed after upgrading from Vista&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 82.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=110&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Access Gateway Standard Edition&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Planned&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 76.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=102&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not yet available&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 78.7pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=105&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;In development&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 82.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=110&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Access Gateway Advanced Edition 4.5 HF4&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Available now&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 76.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=102&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.citrix.com/site/SS/downloads/results.asp?productID=15005" mce_href="http://www.citrix.com/site/SS/downloads/results.asp?productID=15005"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 78.7pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=105&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;VPN client must be re-installed after upgrading from Vista&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 82.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=110&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Access Gateway Advanced Edition&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Planned&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 76.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=102&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not yet available&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 78.7pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=105&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;In development&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 82.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=110&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;X86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Access Gateway Enterprise Edition 9.0&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Available now&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 76.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=102&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.citrix.com/site/SS/downloads/results.asp?productID=15005" mce_href="http://www.citrix.com/site/SS/downloads/results.asp?productID=15005"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 78.7pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=105&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Requires server build 9.0.68 or later.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 82.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=110&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Access Gateway Enterprise Edition&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Planned&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 76.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=102&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not yet available&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 78.7pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=105&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;In development&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 82.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=110&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087532 name=_Toc228087532&gt;&lt;/A&gt;&lt;A title=z5 name=z5&gt;&lt;/A&gt;&lt;SPAN&gt;F5&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; WIDTH: 399.75pt; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 width=533 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 55.55pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=74&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 50.3pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=67&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 46.4pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=62&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 81pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=108&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 55.55pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=74&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSLVPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 50.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=67&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Build Stage&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 46.4pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=62&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Post v.6.03&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 81pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=108&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Q3 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://tech.f5.com/" mce_href="http://tech.f5.com/"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 55.55pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=74&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSLVPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 50.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=67&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Build Stage&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 46.4pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=62&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Post v.6.03&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 81pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=108&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Q3 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://tech.f5.com/" mce_href="http://tech.f5.com/"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087533 name=_Toc228087533&gt;&lt;/A&gt;&lt;A title=z6 name=z6&gt;&lt;/A&gt;&lt;SPAN&gt;Juniper&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 43.85pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=58&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 81.6pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=109&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 116.4pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=155&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 43.85pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=58&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;6.5R1 or 6.5Rx&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 81.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=109&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Q3 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="https://www.juniper.net/customers/csc/software/ive/" mce_href="https://www.juniper.net/customers/csc/software/ive/"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 116.4pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=155&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;You must have a Juniper.net customer or partner user account.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Contact a Juniper sales representative.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 43.85pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=58&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not shared&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 81.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=109&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Q3 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="https://www.juniper.net/customers/csc/software/ive/" mce_href="https://www.juniper.net/customers/csc/software/ive/"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 116.4pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=155&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;You must have a Juniper.net customer or partner user account.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Working with limited testing. Juniper’s QA has reported that there are no issues seen, both with upgrade and new install scenarios.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;For more information:&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.juniper.net/products_and_services/ssl_vpn_secure_access/" mce_href="http://www.juniper.net/products_and_services/ssl_vpn_secure_access/"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 43.85pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=58&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;X64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 81.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=109&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not yet available&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 116.4pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=155&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Contact a Juniper sales representative.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087534 name=_Toc228087534&gt;&lt;/A&gt;&lt;A title=z7 name=z7&gt;&lt;/A&gt;&lt;SPAN&gt;NCP&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.5in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=144&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 103.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=138&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;IPsec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;9.12&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.5in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=144&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 103.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=138&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;Contact NCP or an NCP dealer representative.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;IPsec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;9.12&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.5in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=144&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 103.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=138&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;Contact NCP or an NCP dealer representative.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;8&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.5in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=144&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: April 2009&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 103.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=138&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;Contact NCP or an NCP dealer representative.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 66.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=89&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;8&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 1.5in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=144&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: April 2009&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 103.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=138&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&amp;nbsp;Contact NCP or an NCP dealer representative.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087535 name=_Toc228087535&gt;&lt;/A&gt;&lt;A title=z8 name=z8&gt;&lt;/A&gt;&lt;SPAN&gt;NetGear&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=MsoNormal&gt;NetGear’s native VPN client is not supported on Windows&amp;nbsp;7. Instead, the following routers have been tested and work with the Windows&amp;nbsp;7 native VPN client. &lt;/P&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 44.8pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 56.6pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=75&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Router&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 127.35pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=170&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 44.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 56.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=75&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;FVX538&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;V3.0.5-23&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 127.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=170&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Sept 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.netgear.com/Products/VPNandSSL.aspx" mce_href="http://www.netgear.com/Products/VPNandSSL.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 44.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 56.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=75&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;FVS338&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;V3.0.5-23&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 127.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=170&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Sept 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.netgear.com/Products/VPNandSSL.aspx" mce_href="http://www.netgear.com/Products/VPNandSSL.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 44.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 56.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=75&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;DGFV338&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;V3.0.5-23&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 127.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=170&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Sept 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.netgear.com/Products/VPNandSSL.aspx" mce_href="http://www.netgear.com/Products/VPNandSSL.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 44.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 56.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=75&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;FVS336G&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;V3.0.5-23&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 127.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=170&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Sept 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.netgear.com/Products/VPNandSSL.aspx" mce_href="http://www.netgear.com/Products/VPNandSSL.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 44.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 56.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=75&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;FVG318&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;V2.1.3-10&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 127.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=170&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Sept 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.netgear.com/Products/VPNandSSL.aspx" mce_href="http://www.netgear.com/Products/VPNandSSL.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 44.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 56.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=75&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SRXN3205&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;V3.0.3-19&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 127.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=170&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Sept 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.netgear.com/Products/VPNandSSL.aspx" mce_href="http://www.netgear.com/Products/VPNandSSL.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087536 name=_Toc228087536&gt;&lt;/A&gt;&lt;A title=z9 name=z9&gt;&lt;/A&gt;&lt;SPAN&gt;Nortel&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 52.2pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=70&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 42.3pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=56&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Date&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 93.95pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=125&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 52.2pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=70&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 42.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=56&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;10.01&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: May 2009&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 93.95pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=125&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://support.nortel.com/go/main.jsp" mce_href="http://support.nortel.com/go/main.jsp"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Only Nortel customers and partners will be able to download the client.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Contact your Nortel Representative&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 52.2pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=70&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 42.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=56&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;10.01&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: May 2009&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 93.95pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=125&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://support.nortel.com/go/main.jsp" mce_href="http://support.nortel.com/go/main.jsp"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Only Nortel customers and partners will be able to download the client.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Contact your Nortel Representative&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 52.2pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=70&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 42.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=56&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;10.01&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: May 2009&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 93.95pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=125&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://support.nortel.com/go/main.jsp" mce_href="http://support.nortel.com/go/main.jsp"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Only Nortel customers and partners will be able to download the client.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Contact your Nortel Representative&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 35.8pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=48&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SSL VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;beta&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 52.2pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=70&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 42.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=56&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;10.01&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 58.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=78&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: May 2009&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 93.95pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=125&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://support.nortel.com/go/main.jsp" mce_href="http://support.nortel.com/go/main.jsp"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Only Nortel customers and partners will be able to download the client.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Contact a Nortel Representative&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087537 name=_Toc228087537&gt;&lt;/A&gt;&lt;A title=z10 name=z10&gt;&lt;/A&gt;&lt;SPAN&gt;SafeNet&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=MsoNormal&gt;The existing SoftRemote version of the SafeNet VPN client is not supported on either 32-bit or 64-bit versions of Windows&amp;nbsp;7. The IPsec Toolkit version named QuickSec, is supported on Windows 7.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 43.85pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=58&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 90.6pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=121&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 99pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=132&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPSec Toolkit&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 43.85pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=58&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86, x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;QuickSec&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 90.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=121&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Expected availability: Q4 2009&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://biz.safenet-inc.com/index.asp" mce_href="http://biz.safenet-inc.com/index.asp"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 99pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=132&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="http://www.safenet-inc.com/products/vpn/softRemote.asp" mce_href="http://www.safenet-inc.com/products/vpn/softRemote.asp"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 63pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=84&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087538 name=_Toc228087538&gt;&lt;/A&gt;&lt;A title=z11 name=z11&gt;&lt;/A&gt;&lt;SPAN&gt;Sonic Wall&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 40.3pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=54&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Release&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Platform&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 54.35pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 55.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=74&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Date&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 51.6pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=69&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Download URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;More information&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Tested on Windows 7 build&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 40.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=54&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPsec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 54.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;4.2.6.0305&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 55.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=74&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta Available&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 51.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=69&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="https://www.mysonicwall.com/Firmware/DownloadCenter.aspx" mce_href="https://www.mysonicwall.com/Firmware/DownloadCenter.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;You must have a mysonicwall.com user account to download.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 40.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=54&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPsec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x64&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 54.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;4.2.6.0305&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 55.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=74&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Beta Available&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 51.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=69&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="https://www.mysonicwall.com/Firmware/DownloadCenter.aspx" mce_href="https://www.mysonicwall.com/Firmware/DownloadCenter.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;You must have a mysonicwall.com user account to download.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7000&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 40.3pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=54&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;IPsec VPN&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 45pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=60&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Final&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 49.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=66&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;x86&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 54.35pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;4.0.0.830&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 55.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=74&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;10/8/2007&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 51.6pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=69&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;A href="https://www.mysonicwall.com/Firmware/DownloadCenter.aspx" mce_href="https://www.mysonicwall.com/Firmware/DownloadCenter.aspx"&gt;&lt;SPAN&gt;Click Here&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;You must have a mysonicwall.com user account to download.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Requires reinstall after Windows upgrade. Upgrade advice will be shown to the user for this client version. Clean Installation works.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 0.75in; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=72&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc228087539 name=_Toc228087539&gt;&lt;/A&gt;&lt;A title=z12 name=z12&gt;&lt;/A&gt;&lt;SPAN&gt;Issues, Resolutions, and Status&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=MsoNormal&gt;The following table contains a list of issues identified during application compatibility testing with the respective resolution or status.&lt;/P&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=TablewithHeader border=1 cellSpacing=0 cellPadding=0 class="TablewithHeader"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: gray 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=101&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Client Application Name&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;VPN Vendor&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Client Application Version&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Known Issue&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: gray 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BACKGROUND: rgb(217,217,217); BORDER-TOP: gray 1.5pt solid; BORDER-RIGHT: gray 1.5pt solid; PADDING-TOP: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 11pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 9pt"&gt;Solution&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=101&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Cisco VPN Client&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;CISCO&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;5.0.05.0280&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Blue screen crash on reboot after installation.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Fixed.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=101&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Secure Client&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;CheckPoint&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;NGX_R60_HFA2&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Upgrade Issue - flag for block.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not a regression.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;An upgrade notice is shown during upgrade because the client uses .NET class drivers which are not migrated during upgrade. Users can uninstall and reinstall after upgrade.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top rowSpan=2 width=101&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Citrix Access Gateway&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top rowSpan=2 width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Citrix&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Citrix access gateway (CAG) client version 4603301&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Citrix VPN Client is not giving IP address.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Reported on MS-Connect site for 64-bit version. Though we cannot currently reproduce this, our ISV engagement team is working work with Citrix to investigate the issue.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Citrix has confirmed that their client works on clean installation. Citrix is in the planning/development stage for 64-bit.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Citrix access gateway (CAG) client version 4603301&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;CAG unable to complete connection setup and hangs while Applying Network Policy&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not a regression.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;An upgrade notice is shown during upgrade because the client uses .NET class drivers which are not migrated during upgrade. Users can reinstall (without having to first uninstall) after the upgrade.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top rowSpan=3 width=101&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Soft Remote&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top rowSpan=3 width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SafeNet&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;10.8.4 (32-Bit)&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Failed to install adapter due to hard version check in the driver.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;The VA does not function properly.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top rowSpan=3 width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not a regression.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;An upgrade notice is shown during upgrade that this client application will not work as the client is supported on Windows&amp;nbsp;Vista only.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SafeNet’s IPsec toolkit called QuickSec is scheduled to support Windows&amp;nbsp;7 in 2009 Q4.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;11.1.2 (32-Bit)&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;While installing, qsfilter.sys crashes.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;11.1.2 (64-Bit)&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Fails to install. due to a hard version check.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=101&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Global Network Client Managed VPN &lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;AT&amp;amp;T&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;7.6.0.3005&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Network access client does not work.&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;AT&amp;amp;T working on the fix. Not Windows&amp;nbsp;7specific issue&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=101&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SonicWall Global VPN Client&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;SonicWall&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;4.0.0&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Get an error: Failed to open the IPSec driver&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Not a regression.&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Users can uninstall and reinstall after upgrade. Clean installation on&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;works fine.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: 1.5pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 75.75pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=101&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Secure Entry Client&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 67.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=90&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;NCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 85.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=114&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;8, 9.12&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 121.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1pt solid; PADDING-TOP: 0in" vAlign=top width=162&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Version check issue&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: 1.5pt solid; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 4.3pt; WIDTH: 139.5pt; PADDING-RIGHT: 4.3pt; BORDER-TOP: medium none; BORDER-RIGHT: 1.5pt solid; PADDING-TOP: 0in" vAlign=top width=186&gt;
&lt;P style="LINE-HEIGHT: 12pt" class=MsoNormal&gt;Fixed by NCP.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=TableSpacing&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3235576" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Troubleshooting/">Troubleshooting</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/3rd+Party/">3rd Party</category></item><item><title>Smart Defaults for VPN Strategy and Authentication Protocol in CMAK</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/04/09/smart-defaults-for-vpn-strategy-and-authentication-protocol-in-cmak.aspx</link><pubDate>Thu, 09 Apr 2009 20:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3224609</guid><dc:creator>rrasblog</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3224609</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/04/09/smart-defaults-for-vpn-strategy-and-authentication-protocol-in-cmak.aspx#comments</comments><description>&lt;FONT size=3 face=Calibri&gt;
&lt;P style="MARGIN: 0cm 0cm 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;In W7 the CMAK wizard can be used to create CM profiles that can run on both Vista and W7 machines (a separate profile is still required for XP). When creating the profile if a VPN strategy or authentication protocol&amp;nbsp;is specified which is not supported by Vista&amp;nbsp;then CMAK automatically assigns default values for these settings for Vista. In this blog i will explain what these smart default values are &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-add-space: auto" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;·&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 7pt; mso-fareast-font-family: Symbol"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;If ‘Try IKEv2 only’ or ‘Try IKEv2 First’ VPN strategy is chosen then by default ‘Try SSTP first’ and ‘Try PPTP first’ are assigned for Vista SP1 and Vista RTM respectively&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;·&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 7pt; mso-fareast-font-family: Symbol"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;With any of the VPN strategies if the authentication protocol chosen is EAP-MSCHAPv2 then by default MSCHAPv2 is assigned for Vista SP1 and Vista RTM &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-add-space: auto" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;The above settings can be changed through the Advanced Customization option in the CMAK wizard&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;For detail description on the order in which tunnels are tried for every VPN strategy and deployment recommendations for managing mixed client and server OS version scenarios refer to &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi"&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2009/02/11/vpn-tunnel-strategy-defining-the-connection-order-between-various-tunnel-types.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/02/11/vpn-tunnel-strategy-defining-the-connection-order-between-various-tunnel-types.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;this&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt; comprehensive blog written by Samir&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Aanand Ramachandran&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Program Manager, RRAS&lt;/FONT&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3224609" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Remote Access Deployment – Part 3: Configuring RADIUS Server for remote access</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/25/remote-access-deployment-part-3-configuring-radius-server-for-remote-access.aspx</link><pubDate>Wed, 25 Mar 2009 11:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3217799</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3217799</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/25/remote-access-deployment-part-3-configuring-radius-server-for-remote-access.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In this post, I will go through the steps to configure to deploy Network Policy Server (NPS) based RADIUS server to authenticate and authorize the remote access connections coming from RRAS based VPN server. I will try to go through different policy parameters in order to point you to various important policy options in NPS server role. However for your deployment, you may be adding/deleting more these depending upon your requirements.&lt;/p&gt;  &lt;p&gt;Radius server is used to perform AAA i.e. authentication, authorization and accounting of the remote access user.&lt;u&gt; This post gives details on Network Policy server (NPS) role acting as RADIUS server – installed on a different machine from the one running RRAS server&lt;/u&gt;. &lt;/p&gt;  &lt;h5&gt;3.1 Installation of server role&lt;/h5&gt;  &lt;p&gt;Let us try to configure NPS server role as a RADIUS server on a Windows server 2008 R2 machine. To do that, you need to first &lt;b&gt;install the NPS&lt;/b&gt; server role: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open “Server Manager”. Click on “Roles”, “Add Roles”. Click “Next”. Select “Network Policy and Access Services”. Click on “Network Policy Server. Click “Next” to install the same.&lt;/li&gt; &lt;/ul&gt;  &lt;h5&gt;3.2 Configuration of Radius server&lt;/h5&gt;  &lt;p&gt;To configure NPS based Radius server to authenticate VPN based remote access connection, follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open Network Policy Server MMC by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Network Policy Server”. This launches the NPS MMC snap-in. &lt;/li&gt;    &lt;li&gt;Click on left pane - “RADIUS Client and Servers”. Click on “&lt;strong&gt;RADIUS Client&lt;/strong&gt;”. This is used to configure the information of RADIUS clients (i.e. RRAS based VPN server in this scenario) that sends authentication and accounting request to this radius server. Right click “New” to create a new entry and enter the RADIUS client information (i.e. IP address and shared secret of the RADIUS client machine i.e. RRAS server machine).&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Note: This needs to be configured &lt;strong&gt;only&lt;/strong&gt; if the RADIUS Client and NPS server are running on separate machines. &lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;Click on “&lt;strong&gt;Remote RADIUS Server Group&lt;/strong&gt;”. This is used when this machine is running as a RADIUS PROXY - configure the information about the RADIUS server to which this machine will forward authentication and accounting requests.&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;For this example scenario where RADIUS server is authentication the connection locally, skip this configuration.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;Click on “Policies”, then click on “&lt;strong&gt;Connection Request Policies&lt;/strong&gt;”. CRP allows you to designate whether connection requests are processed locally or forward to remote RADIUS server group. &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Right click New – to create a new CRP. The specific fields in Connection Request policy of interest are: - &lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;li&gt;“Type of network access server” - set it to “Remote Access Server (VPN-Dial up)” &lt;/li&gt;      &lt;li&gt;“Forwarding Connection Request” Authentication – Select “Authenticate requests on this server” if you are authenticating request locally. OR select “Forward requests to the following remote RADIUS Server group – if getting forwarded” if you this machine is acting as RADIUS proxy and forwarding the request to some other machine running RADIUS server.&lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;For this example scenario where RADIUS server is authentication the connection locally, select “Authenticate requests on this server”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;li&gt;“Authentication Methods” – this can be set at the CRP level or at the network policy level. If set at CRP level – this will override the authentication setting at the individual policy level.&lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;For this example scenario, let the authentication methods be set at the policy level.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;Click on “Policies” node, then click on &lt;strong&gt;”Network Policies&lt;/strong&gt;” node. Network policies allow you to designate who is authorized to connect to the network and the circumstance under which they can or cannot connect. &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Right click New – to create a new network policy. A network access policy has different fields, however some of the common fields are given below: -&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Note: The &lt;strong&gt;mandatory&lt;/strong&gt; ones that are required for remote access connection to pass through are highlighted in &lt;b&gt;bold: -&lt;/b&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;li&gt;&lt;u&gt;Overview&lt;/u&gt;:         &lt;ul&gt;         &lt;li&gt;“Type of network access server” - set it to “Remote Access Server (VPN-Dial up)” – to specify the type of Radius client which can match this policy. &lt;/li&gt;          &lt;li&gt;“&lt;b&gt;Access Permission&lt;/b&gt;” – should be set to “Grant access” – to specify the access permission if conditions and constraints of the policy match against the connection request.&lt;/li&gt;       &lt;/ul&gt;     &lt;/li&gt;      &lt;li&gt;&lt;u&gt;Condition&lt;/u&gt;: If ALL the conditions match against the connection request, NPS uses this policy to authorize the connection request, else skips this policy and evaluates other policies (if configured)         &lt;ul&gt;         &lt;li&gt;“Operating System” – specifies the OS for remote access client computer to match this policy &lt;/li&gt;          &lt;li&gt;“Windows Groups” – This condition specifies the remote access user’s group inside Active directory.&lt;/li&gt;       &lt;/ul&gt;     &lt;/li&gt;      &lt;li&gt;&lt;u&gt;Constraints&lt;/u&gt;: If ALL the constraints are not matched by the connection request, the network access is denied for the connection.         &lt;ul&gt;         &lt;li&gt;“&lt;b&gt;Authentication Methods&lt;/b&gt;” – select access &lt;b&gt;**only**&lt;/b&gt; to those remote access clients that authenticate with specific authentication protocols&lt;/li&gt;       &lt;/ul&gt;     &lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Note: This list &lt;strong&gt;MUST&lt;/strong&gt; match the authentication methods configured inside RRAS server.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;ul&gt;       &lt;li&gt;“Day and time restrictions” – Allow access to remote access users &lt;b&gt;**only** &lt;/b&gt;on these days and at these times&lt;/li&gt;     &lt;/ul&gt;      &lt;li&gt;&lt;u&gt;Settings&lt;/u&gt;: If conditions and constraints match the connection request and the policy grants access, then the settings are applied on top of the connection.         &lt;ul&gt;         &lt;li&gt;“Idle Timeout” – specify the maximum time to remain idle before connection is disconnected. &lt;/li&gt;          &lt;li&gt;“IP Filters” – To be applied to the VPN connection to restrict the remote access user to specify IP addresses. &lt;/li&gt;          &lt;li&gt;“NAP Enforcement” – specify whether you want to enforce NAP for this policy. Note: This will require additional configuration as highlighted in &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=729bba00-55ad-4199-b441-378cc3d900a7&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=729bba00-55ad-4199-b441-378cc3d900a7&amp;amp;displaylang=en"&gt;this&lt;/a&gt; step-by-step guide.&lt;/li&gt;       &lt;/ul&gt;     &lt;/li&gt;   &lt;/ul&gt;    &lt;li&gt;Click on “&lt;strong&gt;Accounting&lt;/strong&gt;” – to select your preference on the logging store for the accounting data –SQL or a file.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;References: &lt;/b&gt;For further details on Radius configuration, please refer to &lt;a href="http://www.microsoft.com/technet/community/columns/cableguy/cg0404.mspx" mce_href="http://www.microsoft.com/technet/community/columns/cableguy/cg0404.mspx"&gt;this&lt;/a&gt; article. For further details on remote access policy configuration, please refer to &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=8168740a-0c64-49e3-a6d8-dd6309111fca&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=8168740a-0c64-49e3-a6d8-dd6309111fca&amp;amp;displaylang=en"&gt;this&lt;/a&gt; document.&lt;/p&gt;  &lt;h5&gt;3.3 Further Readings&lt;/h5&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-1-configuring-remote-access-clients.aspx"&gt;Remote Access Deployment – Part 1: Configuring Remote Access Clients&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx"&gt;Remote Access Deployment – Part 2: Configuring RRAS as a VPN server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3217799" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category></item><item><title>Remote Access Deployment – Part 2: Configuring RRAS as a VPN server</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx</link><pubDate>Wed, 25 Mar 2009 11:31:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3217793</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3217793</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In this post, I will go through the steps to configure to deploy RRAS as a VPN server. I will try to go through different configuration scenarios in order to point you to various configuration options in RRAS server role. However for your deployment, you may be skipping some of those – depending upon your requirements.&lt;/p&gt;  &lt;p&gt;Terminology: &lt;b&gt;RRAS Internal Interface&lt;/b&gt; is the interface representing all remote access devices (all VPN/dial-up clients are part of this interface). &lt;/p&gt;  &lt;p&gt;Lets go through the different steps: -&lt;/p&gt;  &lt;h5&gt;2.1 Installation of server role&lt;/h5&gt;  &lt;p&gt;Let us try to configure RRAS server role as a VPN server on a Windows server 2008 R2 machine. To do that, you need to first &lt;b&gt;install the RRAS&lt;/b&gt; server role: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open “Server Manager”. Click on “Roles”, “Add Roles”. Click “Next”. Select “Network Policy and Access Services”. Click on “Routing and Remote Access Service” and the underlying checkboxes. If you want to install NPS based radius server on the same machine as RRAS server, select the same too. Click “Next” to install the same. &lt;/li&gt; &lt;/ul&gt;  &lt;h5&gt;2.2 Configuring for VPN server&lt;/h5&gt;  &lt;p&gt;Once the server role is installed, you need to configure the same to provision the server role as a VPN server. To do the same, follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open Routing and Remote Access MMC snap-in by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Routing And Remote Access”. This launches the RRAS MMC snap-in. &lt;/li&gt;    &lt;li&gt;Right Click on the left pane – on the machine name (below “Server Status”) and select “Configure and Enable Routing and Remote Access”. Click “Next”. &lt;/li&gt;    &lt;li&gt;Select “Remote access (dial-up or VPN)”. Click “Next”. &lt;/li&gt;    &lt;li&gt;Select “VPN”. Click “Next”. &lt;/li&gt;    &lt;li&gt;Select the network interface card (NIC) connected towards the Internet. This is your public interface. And automatically the other interfaces are considered as private interface by RRAS. &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;If you plan to deploy RRAS serve directly connected to Internet and want to enable RRAS packet filters to allow **only VPN traffic** to be accepted from Internet side, click on “Enable security on the selected interface by setting up static packet filters”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;WARNING:&lt;/b&gt; If you are running other server roles (e.g. terminal server) on the same machine that needs access from the Internet side, you need to MANUALLY go and add those filters to allow access to those server roles. Otherwise, the RRAS packet filters will drop those packets. &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Click “Next”&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;On the “IP Address Assignment” page, select the mechanism by which you will like to assign the IPv4 addresses to the remote access clients (i.e. client’s inner IP address – through which they access the machines sitting on private interface of RRAS). &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;By default, “Automatically” is set on. This mandates a need for DHCP server to be sitting on the private interface of RRAS. In this scenario, RRAS server obtains IP addresses on behalf of remote access clients using DHCP protocol and then assigns these addresses to the VPN clients when they connect in. Click “Next” to continue.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;If you will like to specify the IP address from a static pool, select “From a specified range of addresses”. And select “Next”. In the next page, select “New” and you can enter the Address range (e.g. 192.168.1.1 to 192.168.1.10). Click “Next” to continue.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;You will see “Managing Multiple Remote Access Servers” page. Here you can select how you want to authenticate the remote access clients. There are two options here:      &lt;ul&gt;       &lt;li&gt;“No, use Routing and Remote Access to authenticate connection requests”. Select this option, if you will like to use Windows based authentication. This mechanism will require your remote access server machine to be joined to domain if you will like to authenticate the remote access users using domain credentials. &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;WARNING&lt;/strong&gt;: It is not recommended for edge machines to be joined to domain – in order to restrict the security foot-print of a DMZ machine.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;If you will like to authenticate the remote access users using work-group credentials – then RRAS server need not be joined to domain.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;li&gt;“Yes, set up this server to work with a RADIUS server”. Select this option, if you will like to use Radius based authentication. In this scenario there are two options: RADIUS server installed on some other machine or on the RRAS server machine. &lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;WARNING&lt;/strong&gt;: If Radius server is installed on the same machine, then same restriction of machine to be joined to domain exists in order to authenticate remote access users using domain credentials. And it makes an edge machine joined to domain.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Hence the recommended deployment scenario is RADIUS server installed on some other machine sitting on private interface of RRAS server. And that machine is joined to domain, however RRAS server is a non-domain joined machine.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Select “Yes, set-up this server to work with a RADIUS server”. Click “Next”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;The next page is “RADIUS Server Selection” where you can enter the IP address of Primary and alternate RADIUS server (if any) and the shared secret.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;NOTE: The same shared secret must be configured on the RADIUS server as the secret of the RADIUS client (i.e. VPN server in this scenario).&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;Click “Finish” to finish installation of remote access role. &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;If using Windows authentication OR Radius server (i.e. NPS) is installed on the same machine as RRAS server, a pop-up comes which specifies that a default remote access policy named “Microsoft Routing and Remote Access server” is created. Click OK. &lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Additionally in this scenario, you need change the “Access Permission” inside network policy from “Deny access” to “Grant access”. To do this, follow these steps:&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;li&gt;Click on Routing and Remote Access MMC. Click on “Remote Access Logging and Policies”. Right Click and select “Launch NPS”. This will launch NPS MMC (a minimal one though. A full one can be launched by opening nps.msc at the command prompt). &lt;/li&gt;      &lt;li&gt;Double click on the relevant Policy. Click on “Overview” tab and change the “Access Permission” to “Grant Access”. &lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;  &lt;h5&gt;2&lt;a title="_Toc222565997" name="_Toc222565997"&gt;&lt;/a&gt;.3 IPv4 or IPv6 based remote access server&lt;/h5&gt;  &lt;ul&gt;   &lt;li&gt;If not already launched, open Routing and Remote Access MMC snap-in by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Routing And Remote Access”. This launches the RRAS MMC snap-in. &lt;/li&gt;    &lt;li&gt;Right Click on the left pane – on the machine name (below “Server Status”) and select “Properties”. This will open up the property page. &lt;/li&gt;    &lt;li&gt;Click on “General” tab to select at top level how you will like to deploy this RRAS server. For example:      &lt;ul&gt;       &lt;li&gt;To enable RRAS server to forward IPv4 packets to/from remote access clients, enable “IPv4 Remote access server”. &lt;/li&gt;        &lt;li&gt;To enable RRAS server to forward IPv6 packets to/from remote access clients, enable “IPv6 Remote access server”. &lt;/li&gt;        &lt;li&gt;To enable RRAS server to forward IPv4 packets while acting as a site-to-site router, enable “IPv4 Router” and “LAN and demand-dial routing”. &lt;/li&gt;        &lt;li&gt;To enable RRAS server to forward IPv6 packets while acting as a site-to-site router, enable “IPv6 Router” and “LAN and demand-dial routing”. &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Click on IPv4 tab to change IPv4 transport related configuration:      &lt;ul&gt;       &lt;li&gt;“Enable IPv4 Forwarding” should be checked on – to ensure IPv4 packets can be forwarded between remote access client and rest of intranet resources. This check-box should be turned off – only if remote access users need to access the remote access server (e.g. you have some other server roles like IIS installed on remote access server machine and you will like to give your user access to only those server roles and not any other machines). &lt;/li&gt;        &lt;li&gt;You can change the “IPv4 address assignment” between a “static address pool” and “DHCP”. This address pool will be used to assign one IP address to remote access client during VPN tunnel establishment phase. &lt;/li&gt;        &lt;li&gt;If you will like to forward NETBIOS based name resolution queries coming from remote access clients to intranet (or private network behind RRAS server), click on “Enable broadcast name resolution”. &lt;/li&gt;        &lt;li&gt;If you have multiple NICs as private interface on RRAS server, you need to select the NIC which will be used by RRAS server to read the DHCP server, DNS server and WINS server addresses. The DHCP server address will be used to build the IP address pool if “IPv4 address assignment” is DHCP. The DNS server and WINS server address will be passed to remote access clients during VPN tunnel establishment phase. These addresses will be used by remote access client to do the name resolution for intranet resources. &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Click on IPv6 tab to change IPv6 transport related configuration:      &lt;ul&gt;       &lt;li&gt;“Enable IPv6 Forwarding” should be checked on – to ensure IPv6 packets can be forwarded between remote access client and rest of intranet resources. This check-box should be turned off – only if remote access users need to access the remote access server (e.g. you have some other server roles like IIS installed on remote access server machine and you will like to give your user access to only those server roles and not any other machines). &lt;/li&gt;        &lt;li&gt;“Enable Default Route Advertisement” should be checked on – if you will like to make this RRAS server as the default IPv6 gateway for the remote access clients (i.e. turning split-tunneling off for the IPv6 transport in the remote access client) &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Note: This check-box is not available on IPv4 tab – because in case of IPv4 the remote access client’s VPN configuration is the ONLY configuration that governs whether it has default IPv4 gateway towards VPN server or not (i.e. whether split-tunneling is turned on or off). However IPv6 is a special case because IPv6 protocol allows IPv6 router advertisement capability by which VPN server can advertise to VPN clients to become a default. If it does AND the remote access client’s VPN configuration allows that, then only default IPv6 gateway will be set with highest precedence (or lowest metric) on the VPN interface.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;li&gt;“IPv6 Prefix assignment” will be used to enter a /64 bit IPv6 prefix – which will be sent to the remote access clients. For example, 3000:1:2:3: &lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Note: The remote access clients share the same /64 bit IPv6 prefix – with 64 bit interface-id (i.e. lower 64 bit of IPv6 address) being different for each client.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;ul&gt;     &lt;li&gt;If you have multiple NICs as private interface on RRAS server, you need to select the NIC which will be used by RRAS server to read the DNS server’s IPv6 address. &lt;b&gt;This parameter is ONLY used for IKEv2 based VPN connection&lt;/b&gt; – to relay DNS server IPv6 address to the remote access clients during IKEv2 VPN tunnel establishment phase. This address will be used by remote access client to do the name resolution for intranet resources. &lt;/li&gt;   &lt;/ul&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Note: The DNS server IPv6 address for &lt;b&gt;rest of the PPP based VPN tunnels&lt;/b&gt; (i.e. PPTP, L2TP and SSTP) are not configured on the RRAS server directly. For this scenario to work, RRAS server is configured as a DHCPv6 Relay agent with RRAS Internal interface (i.e. virtual interface representing the remote access clients) and private interface facing a DHCPv6 stateless server. The DHCPv6 stateless server is configured with the DNS server IPv6 address. During VPN tunnel establishment phase, remote access client sends a DHCPv6 inform request packet – to get DNS server IPv6 address. This packet is sent over VPN tunnel to RRAS server who then relays the same to DHCPv6 stateless server. A DHCPv6 Inform reply is sent in reverse path containing the IPv6 address of the DNS server. &lt;/p&gt;    &lt;p mce_keep="true"&gt;&amp;#160;&lt;/p&gt; &lt;/blockquote&gt;  &lt;h5&gt;&lt;a title="_Toc225595492" name="_Toc225595492"&gt;&lt;/a&gt;&lt;a title="_Toc222565998" name="_Toc222565998"&gt;&lt;/a&gt;2.4 NAT support&lt;/h5&gt;  &lt;p&gt;RRAS server can be configured as a NAT router for two main scenarios – a) between machines sitting on LAN (i.e. private interface of RRAS) and Internet b) between remote access user machines and Internet.&lt;/p&gt;  &lt;p&gt;To configure RRAS server as a NAT router (address port translation): -&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open Routing and Remote Access MMC snap-in by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Routing And Remote Access”. This launches the RRAS MMC snap-in. &lt;/li&gt;    &lt;li&gt;Click on the left pane – on the machine name (below “Server Status”) and select “IPv4” and “General”. Right click and select “New Routing Protocol” and select “NAT”. &lt;/li&gt;    &lt;li&gt;Select on “NAT” node under “IPv4”. Right click and select “New Interface”.&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Select your interface facing internet and in the next page select the “Public interface connected to the Internet” and click to “Enable NAT on this interface”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Select your interface facing private side (can be RAS Internal interface or other private NIC of RAS). And in the next page select the “Private interface connected to private network”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;h5&gt;&lt;a title="_Toc225595493" name="_Toc225595493"&gt;&lt;/a&gt;2.5 DHCP Relay Agent&lt;/h5&gt;  &lt;p&gt;RRAS server can be configured as a DHCP Relay Agent for two main scenarios – &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Between remote access clients and DHCP server when RRAS server is acting as a VPN server. In this scenario, the relay agent is used to forward DHCP inform packets between VPN client and DHCP server – to obtain information like DNS server address, IP routes. &lt;/li&gt;    &lt;li&gt;Between LAN clients and DHCP server when RRAS server is acting as a LAN router. In this scenario, the relay agent is used to forward all DHCP packets – to obtain IP address and extended information.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;DHCP relay agent is configured for IPv4 or IPv6 – depending upon the transport configured on DHCP client machine. Or in other words, if remote access client is configured to obtain IPv4 address from VPN server, then you need to configure DHCPv4 relay agent on RRAS server. And same way, if remote access client is configured to obtain IPv6 prefix from VPN server, then you need to configure DHCPv6 relay agent on RRAS server.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Note: DHCPv6 Relay Agent MUST&lt;/b&gt; be installed on RRAS server to support IPv6 remote access server scenario for &lt;b&gt;all PPP based VPN tunnels&lt;/b&gt; (i.e. PPTP, L2TP and SSTP). This is required because the DNS server IPv6 address can be relayed to the VPN client only via the DHCPv6 Inform mechanism and not via PPP IPv6 Configuration Protocol stage. However the DHCPv4 Relay Agent is optional because DNS server address can be relayed to VPN client via PPP IPCP stage. The &lt;b&gt;DHCPv6 Relay is optional for IKEv2 VPN&lt;/b&gt; tunnel because DNS server IPV6 address can be relayed to the VPN client using IKEv2 configuration payload stage.&lt;/p&gt;  &lt;p&gt;To configure RRAS server as a DHCPv4 Relay Agent: -&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;If not already launched, open Routing and Remote Access MMC snap-in by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Routing And Remote Access”. This launches the RRAS MMC snap-in. &lt;/li&gt;    &lt;li&gt;Click on the left pane – on the machine name (below “Server Status”) and select “IPv4” and “General”. Right click and select “New Routing Protocol” and select “DHCP Relay Agent”. &lt;/li&gt;    &lt;li&gt;Select on “DHCP Relay Agent” node under “IPv4”. Right click and select “New Interface”.&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Select your interface facing DHCP server and in the next page configure the DHCP relay agent parameters.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Repeat the same steps to select your interface facing remote access client (e.g. Internal) and in the next page configure the DHCP relay agent parameters.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;Select on “DHCP Relay Agent” node under “IPv4”. Right click and select “Properties”. Enter the IPv4 address of the DHCP server – to which to relay the requests.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To configure RRAS server as a DHCPv6 Relay Agent: -&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;If not already launched, open Routing and Remote Access MMC snap-in by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Routing And Remote Access”. This launches the RRAS MMC snap-in. &lt;/li&gt;    &lt;li&gt;Click on the left pane – on the machine name (below “Server Status”) and select “IPv6” and “General”. Right click and select “New Routing Protocol” and select “DHCPv6 Relay Agent”. &lt;/li&gt;    &lt;li&gt;Select on “DHCPv6 Relay Agent” node under “IPv6”. Right click and select “New Interface”.&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Select your interface facing DHCP server and in the next page configure the DHCP relay agent parameters.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Repeat the same steps to select your interface facing remote access client (e.g. Internal) and in the next page configure the DHCP relay agent parameters.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;Select on “DHCPv6 Relay Agent” node under “IPv6”. Right click and select “Properties”. Enter the IPv6 address of the DHCP server – to which to relay the requests.&lt;/li&gt; &lt;/ul&gt;  &lt;h5&gt;2.6 Packet Filtering&lt;/h5&gt;  &lt;p&gt;RRAS server can be configured to enable stateless packet filtering on any interface (LAN as well as Internal interface) using source IP address, destination IP address, IP protocol type, source and destination port number (for IP protocol type as TCP/UDP). These filters can be set for IPv4 as well as IPv6 packets.&lt;/p&gt;  &lt;p&gt;To enable RRAS packet filtering on LAN interface (e.g. accept only VPN packets on public interface), please follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;If not already launched, open Routing and Remote Access MMC snap-in by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Routing And Remote Access”. This launches the RRAS MMC snap-in. &lt;/li&gt;    &lt;li&gt;Click on the left pane – on the machine name (below “Server Status”) and select “IPv4” and “General”. Select the appropriate LAN interface on the right side. And right click and select “Properties”. &lt;/li&gt;    &lt;li&gt;Select the “Inbound Filters” to add the filters on the IPv4 packets coming &lt;b&gt;into &lt;/b&gt;the interface and “Outbound Filters” to add the filters on the IPv4 packets going &lt;b&gt;out&lt;/b&gt; of the interface. On clicking the same, you can select the filter action (e.g. the incoming side filter action is “drop all packets except those that match the criteria below”) and click “New” to add the filter. &lt;/li&gt;    &lt;li&gt;Similarly you can add the filters on IPv6 packets.&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;SECURITY NOTE: &lt;/b&gt;It is strongly recommended to &lt;b&gt;allow specific filters&lt;/b&gt; on the public interface of RRAS and drop the rest. This filter set should match all the server roles running on RRAS server and accessible from Internet side (e.g. VPN service). Additionally, &lt;b&gt;the IP address in the filter&lt;/b&gt; must be set correctly i.e. destination IP address MUST match the IP address of RRAS server public interface on the &lt;i&gt;inbound filters &lt;/i&gt;and source IP address in packet MUST match the IP address of RRAS server public interface on the &lt;i&gt;outbound filters&lt;b&gt;.&lt;/b&gt;&lt;/i&gt;&lt;b&gt; &lt;/b&gt;If you don’t put IP addresses explicitly, there is a risk of IP packets getting forwarded across RRAS server not meant for services running on RRAS server.&lt;b&gt;&lt;/b&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;To enable RRAS packet filtering on VPN interface (i.e. filters packets coming in from remote access clients or going to remote access clients), please follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open the remote access network policy inside Radius server, go under the “Settings” tab and, click on “IP Filters” and then add the IPv4 and IPv6 inbound/outbound filters. This filter set will be passed to RRAS server during authentication stage and is applied on top of the internal interface corresponding to the specific authenticated VPN client. Note: The IP address given in this filter set represents the IP address of intranet machines (or machines behind RRAS server).&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;Note&lt;/b&gt;: NAP based health check also requires IP filters to be configured to restrict unhealthy client machines to a quarantine zone. However this quarantine filter set is configured as a “Remediation Server Group” and not as “IP filters” attribute inside the policy “Settings” tab. This is because filters specified as remediation server group is added on RRAS server when the remote access client is unhealthy and removed when the client becomes healthy. However the filters specified as IP filters is added on RRAS server when the remote client is healthy for the NAP scenario and for non-NAP scenario when the remote client is authenticated.&lt;/p&gt;  &lt;h5&gt;2.7&lt;a title="_Toc225595495" name="_Toc225595495"&gt;&lt;/a&gt; Tunnel Specific &lt;/h5&gt;  &lt;p&gt;Most of the configuration on RRAS server side is common for different types of VPN tunnels (i.e. PPTP, L2TP, SSTP and IKEv2), however there are few configuration that varies according to the tunnel. Let us take a look at some of these: -&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Number of devices&lt;/b&gt;: A device is a software interface through which the remote access clients connect to VPN server. There is limited number of concurrent devices that is supported by different editions of Windows server – the details given &lt;a href="http://www.microsoft.com/windowsserver2008/en/us/compare-specs.aspx" mce_href="http://www.microsoft.com/windowsserver2008/en/us/compare-specs.aspx"&gt;here&lt;/a&gt;. Based upon your remote access user profile (mainly OS), you may have configured different VPN tunnels on the RRAS servers. You can thereby restrict number of ports for that particular tunnel type by changing the Ports configuration. Open RRAS MMC snap-in, click on the left pane – on the machine name (below “Server Status”) and select “Ports” node. Right click and select “Properties” and then select appropriate tunnel type and click “Configure” – to set the maximum number of concurrent ports supported by a given tunnel. This way you can divide your pool of concurrent VPN devices in a systematic manner between different tunnel types – hence the specific profile of remote access user. &lt;/li&gt;    &lt;li&gt;&lt;b&gt;Machine certificate configuration&lt;/b&gt;: L2TP/IPSec, SSTP and IKEv2 tunnels require a machine certificate to be installed on the RRAS server. This machine certificate should have following properties: EKU as Server Authentication, Subject Name same as the hostname OR IP address configured inside VPN client configuration and part of Trusted Root Chain that is also present on the VPN client machine. The same certificate can be used for all the tunnel types.&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;This certificate must be installed inside the local machine certificate store – under “Personal”. For L2TP/IPSec and IKEv2 – no other extra configuration is required in order to communicate the certificate pointer to RRAS. However for SSTP tunnel configuration, it is recommended to cross-check that the appropriate certificate is pointed by SSL Certificate Binding found here: Open RRAS MMC snap-in, click on server name, right click and select “Properties” and click on “Security” tab.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Authentication Methods/Protocols&lt;/b&gt;: All the VPN tunnels support EAP based authentication protocols. However PPTP &amp;amp; SSTP additionally supports MSCHAPv2, L2TP/IPSec additionally supports MSCHAPv2 and machine certificate based authentication, IKEv2 additionally supports machine certificate based authentication.&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;The set of allowed authentication methods are configured at two locations&lt;/b&gt;: One inside the Radius policy (as given above). And secondly, RRAS server MUST be configured to accept the appropriate authentication methods. This is done by following these steps: Open RRAS MMC snap-in, click on server name, right click and select “Properties” and click on “Security” tab. Click on “Authentication Methods” and select the appropriate authentication protocols accepted by RRAS server.&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;IKEv2 specific&lt;/b&gt;: Certain IKEv2 specific configuration like “Network Outage Time”, “Security Association Expiration Time”, “Security Association data size limit” – can be configured by following these steps: Open RRAS MMC snap-in, click on server name, right click and select “Properties” and click on “IKEv2” tab. &lt;/li&gt;    &lt;li&gt;&lt;b&gt;PPP specific&lt;/b&gt; (holds true for PPTP, L2TP and SSTP): Certain PPP specific configuration like “software compression” can be configured by following these steps: Open RRAS MMC snap-in, click on server name, right click and select “Properties” and click on “PPP” tab.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;References: &lt;/b&gt;For further details on SSTP configuration, please refer to &lt;a href="http://download.microsoft.com/download/b/1/0/b106fc39-936c-4857-a6ea-3fb9d1f37063/Deploying%20SSTP%20Remote%20Access%20Step%20by%20Step%20Guide.doc" mce_href="http://download.microsoft.com/download/b/1/0/b106fc39-936c-4857-a6ea-3fb9d1f37063/Deploying%20SSTP%20Remote%20Access%20Step%20by%20Step%20Guide.doc"&gt;this&lt;/a&gt; step-by-step guide.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;References: &lt;/b&gt;For further details on IKEv2 configuration, please refer to &lt;a href="http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc" mce_href="http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc"&gt;this&lt;/a&gt; step-by-step guide.&lt;/p&gt;  &lt;h5&gt;2.8 Further Readings&lt;/h5&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-1-configuring-remote-access-clients.aspx"&gt;Remote Access Deployment – Part 1: Configuring Remote Access Clients&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-3-configuring-radius-server-for-remote-access.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-3-configuring-radius-server-for-remote-access.aspx"&gt;Remote Access Deployment – Part 3: Configuring RADIUS Server for remote access&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3217793" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category></item><item><title>Remote Access Deployment – Part 1: Configuring Remote Access Clients</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/25/remote-access-deployment-part-1-configuring-remote-access-clients.aspx</link><pubDate>Wed, 25 Mar 2009 11:11:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3217784</guid><dc:creator>rrasblog</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3217784</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/25/remote-access-deployment-part-1-configuring-remote-access-clients.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In my last few &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx"&gt;articles&lt;/a&gt;, I discussed about the design guidelines to consider before deploying&amp;#160; a remote access solution. &lt;/p&gt;  &lt;p&gt;In the next few articles, I will go through the steps to configure the various components&amp;#160; of the remote access solution. These articles will act as your jump-start guide to quickly build a solution in your pilot lab, test various combinations and then finally roll-it-out in your production environment. &lt;/p&gt;  &lt;p&gt;All the steps given below are done on my Windows 7 client beta and Windows server 2008 R2 server beta. If you have other flavour of Windows (like Vista, XP, 2008), you may have to change few steps here and there. Hope you find it useful.&amp;#160; &lt;/p&gt;  &lt;p&gt;Here is the first topic on this:&amp;#160; Configuring the remote access clients&lt;/p&gt;  &lt;h5&gt;&lt;a title="_Toc225595486" name="_Toc225595486"&gt;&lt;/a&gt;1.1 In-built VPN client&lt;/h5&gt;  &lt;p&gt;To &lt;b&gt;create a VPN client&lt;/b&gt; using in-built VPN client, please follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open “Control Panel” -&amp;gt; “Network and Sharing Center”. Click on “Set up new connection or network”. This launches a wizard &lt;/li&gt;    &lt;li&gt;Click “Connect to a workplace”, click “Next”, click “Next”, double click on “Use my Internet connection (VPN)”, enter the hostname or IPv4/IPv6 address of the VPN server and specify the VPN connection name (as seen in network tray icon), click next, then enter username/password for the connection, click connect. This will try to connect. &lt;/li&gt;    &lt;li&gt;The above steps will create a VPN client and tries to establish the VPN connection to the server. If that fails for any reason, select “Set-up the connection anyway” – so that configuration is saved.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To &lt;b&gt;change the properties&lt;/b&gt; of VPN client created using in-built VPN client, please follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Click on networking tray – on bottom right side of your desktop. Move the mouse on the appropriate VPN connection name, right-click and select Properties. This launches VPN connection Properties UI. This UI has four tabs – “General”, “Options”, “Security” and “Networking”. &lt;/li&gt;    &lt;li&gt;“General” tab is used to change the VPN server hostname or IP address. Additionally underlying interface (like dial-up or broadband) to connect to public network can be configured – so that when user clicks on “connect” on VPN interface, it will first try to get underlying interface up (if not already) and then establish a VPN connection on top of it. &lt;/li&gt;    &lt;li&gt;“Options” tab is used to configure some general connectivity options like redial attempts, idle disconnect time, etc &lt;/li&gt;    &lt;li&gt;“Security” tab is used to configure the authentication and VPN tunnel options. &lt;b&gt;By default&lt;/b&gt; the in-built VPN client is created with “Type of VPN” tunnel as Automatic (i.e. tunnel order is - try IKEv2 first, if that fails try SSTP, if that fails try PPTP, if that fails try L2TP). However “Type of VPN” can be changed to try specific VPN tunnel. “Advanced settings” button is used for L2TP/IPSec and IKEv2 tunnel type. Various authentication protocols can be configured under “Authentication” heading. To configure EAP based protocols, select the radio button “Use Extensible Authentication Protocol (EAP)” and then select the relevant EAP methods. If you select “Microsoft Protected EAP (PEAP)” to select other configuration like inner EAP method that gets tunneled inside PEAP TLS session and common configuration like “Enforce Network Access Protection”. If you select EAP-MSCHAPv2, you can optionally configure VPN client to pick-up username/password that was entered during Windows login time – avoiding the user to re-enter the credentials when dialing the VPN connection. This is the most commonly deployed scenario. &lt;/li&gt;    &lt;li&gt;“Networking” tab is used to configure the transports (or protocols) that run on top of VPN tunnel. The most common ones are “Internet Protocol Version 4 (TCP/IPv4)” and “Internet Protocol Version 6 (TCP/IPv6)”. Select a particular transport, click on “Properties” to change common fields like default gateway, DNS server address, DNS suffix for the connection etc. If “User default gateway on remote network” is turned on, the VPN client on successful VPN tunnel connection adds the default route on VPN interface with highest precedence. This way all the IP packets (except those destined to local subnet) go to VPN server. If this parameter is turned off, the default route is not added on VPN tunnel. This scenario will require user to add specific network specific route on the VPN interface – in order to reach the corpnet resources.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To &lt;b&gt;connect/disconnect&lt;/b&gt; the VPN connection, please follow these steps: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Click on networking tray – on bottom right side of your desktop. Move the mouse on the appropriate VPN connection name, right-click and select “Connect” (if already disconnected) and select “Disconnect” if already connected). &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To &lt;b&gt;view the status and statistics&lt;/b&gt; of the VPN connection, please follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Click on networking tray – on bottom right side of your desktop. Move the mouse on the appropriate VPN connection name, right-click and select “Status” (if already connected). &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;This will launch the VPN connection status UI – where you can find the IP address of the client (inner and outer IP address), IP address of the server, bytes sent/received on the connection.&lt;/p&gt;  &lt;h5&gt;&lt;a title="_Toc225595487" name="_Toc225595487"&gt;&lt;/a&gt;1.2 CM based VPN client&lt;/h5&gt;  &lt;p&gt;To &lt;b&gt;create a CM&lt;/b&gt; &lt;b&gt;client&lt;/b&gt; &lt;b&gt;package&lt;/b&gt; as a network administrator, you first need to &lt;b&gt;install&lt;/b&gt; “Connection Manager Administration Kit” (CMAK) tool on a Windows 2008 R2 server machine and then run the tool to create a CM package. This is done by following these steps: -&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Open “Server Manager”. Click on “Features”, “Add Features”. Select “Connect Manager Administration Kit”, Click “Next” and install the same. &lt;/li&gt;    &lt;li&gt;Open CMAK by clicking on “Start”-&amp;gt;”All Programs”-&amp;gt;”Administrative Tools”-&amp;gt;”Connection Manager Administration Kit”. This launches the CMAK wizard &lt;/li&gt;    &lt;li&gt;Click “Next”. Select the target OS (i.e. OS of the client machine on which the CM based VPN client will be eventually installed). Note: CM package for Vista and Windows 7 is same. Click “Next”. Select “New profile”. Click “Next”. &lt;/li&gt;    &lt;li&gt;Enter the name of the VPN connection (e.g. “Contoso VPN connection”) and the filename of CM profile or package (e.g. contoso). Click “Next”. Click “Next” to skip the realm name. Click “Next” to skip merging of VPN profiles. &lt;/li&gt;    &lt;li&gt;In the page titled “Add support for VPN connections”, click “Phone book from this profile”. You can then specify the VPN server name or IP address – if there is only one VPN server or cluster of server to which the VPN client connects. However to support scenarios where you have deployed VPN servers at different locations of your corporation (like in different countries), you can specify a list of VPN servers in a .txt file. This text file has a list of VPN servers each tagged with a friendly display name (e.g. Contoso India, Contoso US, etc) – that helps end user to connect to appropriate VPN server. A sample file format looks like:&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;[Settings]&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Message=Select the location closest to your office.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;[VPN Servers]&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Contoso India=vpnserver.contoso.in&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Contoso USA=1.2.3.4&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Click “Next”&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;You will see “Create or Modify a VPN Entry” page with a default VPN entry created. To edit the connection properties, click “Edit”. You will see “Edit VPN Entry” UI through which you can change the connection properties like tunnel and authentication protocol selection, IPv4 and IPv6 properties, DNS suffix etc. &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Once done, click “OK” to come back to previous page. Click “Next”&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;For dial-up access you can specify a phone book file. Turn off the “Automatically download phone book updates” checkbox. Click “Next”. &lt;/li&gt;    &lt;li&gt;You will see “Specify Routing Table Updates” page. Here you can add a list of routing table entries in form of a text file that can be added on the client side after the VPN connection comes up. This is used when you &lt;b&gt;turn off&lt;/b&gt; the “Make this connection the client’s default gateway” in “Create or Modify a VPN Entry” page and enable split-tunneling. In this scenario, you can enter the IP routes of all the subnets/host machines inside your corporate network that can be accessed by the client. The format of the text file is each line containing a route preceded by a command (ADD or DELETE) &lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;Command Destination &lt;strong&gt;MASK &lt;/strong&gt;Netmask Gateway &lt;strong&gt;METRIC &lt;/strong&gt;Metric &lt;strong&gt;IF &lt;/strong&gt;Interface&lt;/p&gt;    &lt;p mce_keep="true"&gt;&amp;#160;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;For example:&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;ADD 192.168.1.0 MASK 255.255.255.0 192.168.2.1 METRIC default IF default&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Click “Next”&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;You will see “Configure Proxy Settings for Internet Explorer”. Here you can add the intranet web proxy settings that will be used after the VPN connection comes up. Click “Next” for default one (i.e. no web proxy configured or required to access the intranet web resources i.e. direct web access without going through proxy). &lt;/li&gt;    &lt;li&gt;You will see “Add Custom Actions” page – where you can add different custom actions by running specific program on specific action. A sample custom action can be – after VPN connection is established (i.e. “post-connect”), download a new CM package file by doing net use to a file server. For more details see link below. Click “Next” to select default one (no actions). &lt;/li&gt;    &lt;li&gt;You can then add a specific bitmap file (.bmp) to display your connection manager package – at the logon time as well as phone book dialog box. Click Next. Click “Next” to select the default one. &lt;/li&gt;    &lt;li&gt;You can then add specific icon file (.ico) to specify the Program Icon and title bar icon of your connection manager package. Click “Next” to select the default one. &lt;/li&gt;    &lt;li&gt;You can then specify the help file (.chm) which your user can refer to. Click “Next” to select the default one. &lt;/li&gt;    &lt;li&gt;You can then specify the support string (e.g. For any issues related to your VPN connectivity, dial 040-12345678) that appears on the logon box. Click “Next” to select the blank one. &lt;/li&gt;    &lt;li&gt;You can then add a text file (.txt) containing the license agreement that should be displayed to users once they install the CM package. Click “Next” to select none. &lt;/li&gt;    &lt;li&gt;Click “Next” to skip adding additional files. Click “Next” to finish. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The &lt;b&gt;above steps generate a CM package&lt;/b&gt; (.exe file) under %windir%\Program Files\CMAK\Profiles\Vista and above\ directory – with appropriate profile name on your server machine.&lt;/p&gt;  &lt;p&gt;You can then &lt;b&gt;send the CM package&lt;/b&gt; (.exe file) to your remote access users using any mechanism – like upload to a file or web server, send via email etc.&lt;/p&gt;  &lt;p&gt;To &lt;b&gt;install the CM package&lt;/b&gt; on the VPN client machine, double click on the CM package file. It will ask whether the package needs to be installed for single user or all users and then it installs the same.&lt;/p&gt;  &lt;p&gt;To &lt;b&gt;change the properties &lt;/b&gt;of the VPN connection (e.g. VPN destination) on the VPN client machine, please follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Click on networking tray – on bottom right side of your desktop. Move the mouse on the appropriate VPN connection name, right-click and select Properties. This launches VPN connection Properties UI. This UI is different from the properties UI of in-the-box VPN client because the goal of CM based package is end user not changing any configuration – i.e. exposing minimal configuration.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To &lt;b&gt;connect/disconnect&lt;/b&gt; the VPN connection, please follow these steps: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Click on networking tray – on bottom right side of your desktop. Move the mouse on the appropriate VPN connection name, right-click and select “Connect” (if already disconnected) and select “Disconnect” if already connected). &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;To &lt;b&gt;view the status and statistics&lt;/b&gt; of the VPN connection, please follow these steps:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Click on networking tray – on bottom right side of your desktop. Move the mouse on the appropriate VPN connection name, right-click and select “Status” (if already connected). &lt;/li&gt;    &lt;li&gt;This will launch the VPN connection status UI – where you can find the IP address of the client (inner and outer IP address), IP address of the server, bytes sent/received on the connection. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;References: &lt;/b&gt;Please refer to &lt;a href="http://technet2.microsoft.com/windowsserver/en/library/d6ab4d9b-16e3-4af6-8a54-509094d912701033.mspx" mce_href="http://technet2.microsoft.com/windowsserver/en/library/d6ab4d9b-16e3-4af6-8a54-509094d912701033.mspx"&gt;this&lt;/a&gt; CM deployment guide and &lt;a href="http://technet2.microsoft.com/windowsserver/en/library/bc5ad16e-7959-47d2-82aa-1b76aaeb2d8f1033.mspx" mce_href="http://technet2.microsoft.com/windowsserver/en/library/bc5ad16e-7959-47d2-82aa-1b76aaeb2d8f1033.mspx"&gt;this&lt;/a&gt; technical reference for further details on the connection manager.&lt;/p&gt;  &lt;h5&gt;1.3 Further Readings&lt;/h5&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx"&gt;Remote Access Design Guidelines – Part 1: Overview&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx"&gt;Remote Access Design Guidelines – Part 2: VPN client software selection&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx"&gt;Remote Access Design Guidelines – Part 3: Tunnel selection, Authentication, Authorization and Accounting&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx"&gt;Remote Access Design Guidelines – Part 4: IP Routing and DNS&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx"&gt;Remote Access Design Guidelines – Part 5: Where to place RRAS server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx"&gt;Remote Access Deployment – Part 2: Configuring RRAS as a VPN server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-3-configuring-radius-server-for-remote-access.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-3-configuring-radius-server-for-remote-access.aspx"&gt;Remote Access Deployment – Part 3: Configuring RADIUS Server for remote access&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3217784" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category></item><item><title>Remote Access Design Guidelines – Part 5: Where to place RRAS server</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx</link><pubDate>Tue, 17 Mar 2009 14:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3213937</guid><dc:creator>rrasblog</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3213937</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In this post, I will highlight on various placement requirements related to RAS server.&lt;/p&gt;  &lt;h5&gt;&lt;a title="_Toc224633154" name="_Toc224633154"&gt;&lt;/a&gt;5.&lt;a title="_Toc222565985" name="_Toc222565985"&gt;&lt;/a&gt;1 NAT Routers&lt;/h5&gt;  &lt;p&gt;A &lt;strong&gt;VPN server machine&lt;/strong&gt; can sit behind a NAT router as long as following requirements are met:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;For SSTP, NAT port redirection or bi-directional should be configured on NAT router – to redirect the HTTPS packets coming in from Internet side to the VPN server. This includes SSTP based HTTPS packets (TCP port 443). &lt;/li&gt;    &lt;li&gt;For PPTP, NAT port redirection or bi-directional should be configured on NAT router – to redirect all the PPTP packets coming in from Internet side to the VPN server. This includes PPTP tunnel control packets (TCP port number 1723) and PPTP tunnel data packets (IP Protocol type as 47 i.e. GRE). &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;L2TP/IPSec or IKEv2 based VPN server can sit behind NAT router – though it is NOT RECOMMENDED – as pointed by &lt;a href="http://support.microsoft.com/kb/885348" mce_href="http://support.microsoft.com/kb/885348"&gt;this&lt;/a&gt; KB article 885348. In case (like for test lab), you need to do this, please follow this configuration: NAT port redirection or bi-directional should be configured on NAT router – to redirect the IPSec packets coming in from Internet side to the VPN server. This includes IKE packets (UDP port 500) and IPSec ESP packets (UDP port 4500).&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Note:&lt;/b&gt; For L2TP/IPSec, IKEv2 and SSTP scenario requires VPN server configured with machine certificate, care must be taken to ensure it is provisioned with appropriate subject name i.e. subject name in the machine certificate on VPN server should match the &amp;lt;hostname OR IP address&amp;gt; &lt;b&gt;configured&lt;/b&gt; &lt;b&gt;as the VPN destination on the VPN client&lt;/b&gt;. This name or IP address in this scenario maps to the NAT router’s public interface.&lt;/p&gt;  &lt;p&gt;On a similar note, a &lt;strong&gt;VPN client machine&lt;/strong&gt; located behind a NAT router will be able to successfully establish a VPN connection as long as following requirements are met: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;For L2TP/IPSec or IKEv2, the NAT-T (or NAT traversal) is enabled on both ends i.e. VPN client and VPN server – which is indeed the case for Windows based VPN client and VPN Server &lt;/li&gt;    &lt;li&gt;For SSTP, no extra change is required as it works over HTTPS which by default is supported by all flavour of NAT router. &lt;/li&gt;    &lt;li&gt;For PPTP, the PPTP editor (or sometimes called as application level gateway) is enabled on NAT router. &lt;/li&gt; &lt;/ul&gt;  &lt;h5&gt;5.&lt;a title="_Toc224633155" name="_Toc224633155"&gt;&lt;/a&gt;2 Packet Filtering&lt;/h5&gt;  &lt;p&gt;A VPN server usually resides on the edge of the corporate network facing Internet and as it’s a boundary server, you should only open IP packets meant for VPN tunnel and drop the rest. This can be done by doing packet filtering in one of the following ways:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Place a network based firewall &lt;i&gt;between Internet and RRAS server.&lt;/i&gt; And allowing only specific ports destined to VPN server. &lt;/li&gt;    &lt;li&gt;Enable Windows based host firewall &lt;i&gt;on the RRAS server&lt;/i&gt;. &lt;/li&gt;    &lt;li&gt;Enable stateless packet filtering &lt;i&gt;on the RRAS server&lt;/i&gt; on the public interface. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The difference between Windows host firewall and RRAS packet filtering can be summarized in following table:    &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td valign="top" width="200"&gt;           &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;&lt;b&gt;Windows Firewall&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;&lt;b&gt;RRAS Packet Filter&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;&lt;b&gt;Comments&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="200"&gt;           &lt;p&gt;Type of Filtering&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;Stateful&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;Stateless&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;Applications which dynamically opens ports like RPC – requires stateful packet filtering&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="200"&gt;           &lt;p&gt;Enforcement point&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;All IP packets destined to or originated from the machine&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;Can be applied on a per-interface basis – like specific LAN interface (e.g. Internet interface), particular VPN client sub-interface&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;RRAS packet filtering is used during NAP enforcement to restrict unhealthy client to a specific quarantine zone&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="200"&gt;           &lt;p&gt;NAT support&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;Can co-exist with same machine working as NAT router&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;Cannot co-exist with same machine working as NAT router&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="200"&gt;           &lt;p&gt;NAT requires stateful packet filtering&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/p&gt;  &lt;p&gt;The ports that should be opened for VPN tunnels are: -&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;VPN Reconnect or IKEv2: UDP Port 500 (IKE), UDP Port 4500 (NAT-T – Data) and IP Protocol 50 (ESP – Data) &lt;/li&gt;    &lt;li&gt;SSTP: TCP Port 443 &lt;/li&gt;    &lt;li&gt;L2TP: UDP Port 500 (IKE), UDP Port 4500 (NAT-T – Data) and IP Protocol 50 (ESP – Data) &lt;/li&gt;    &lt;li&gt;PPTP: TCP Port 1723 (Control) and IP Protocol Type 47 (GRE –Data) &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;For further details, please refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2007/03/30/rras-server-in-lhs-which-one-to-use-windows-firewall-or-rras-filters.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2007/03/30/rras-server-in-lhs-which-one-to-use-windows-firewall-or-rras-filters.aspx"&gt;this&lt;/a&gt; blog on Firewall vs static filters and this &lt;a href="http://blogs.technet.com/rrasblog/archive/2006/06/14/which-ports-to-unblock-for-vpn-traffic-to-pass-through.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2006/06/14/which-ports-to-unblock-for-vpn-traffic-to-pass-through.aspx"&gt;post&lt;/a&gt; on port numbers.&lt;/p&gt;  &lt;h5&gt;5&lt;a title="_Toc222565988" name="_Toc222565988"&gt;&lt;/a&gt;.3 Single NIC scenario&lt;/h5&gt;  &lt;p&gt;Usually VPN server has minimum two NICs – one towards &lt;b&gt;public&lt;/b&gt; side (Internet side) through which client connects and other towards &lt;b&gt;private&lt;/b&gt; side (Intranet side) connected to rest of intranet.&lt;/p&gt;  &lt;p&gt;However RRAS based VPN server can also be deployed in single NIC scenario – specifically in small-medium businesses. In this scenario, RRAS server sits behind a NAT router and has only single NIC. This NIC is used as both public as well as private interface. Or in other words, the VPN tunnel packets come in from VPN client side via this network interface card, encapsulation is removed and then sent back on the same interface to rest of the intranet machines on the LAN. And on reverse side the packet goes back via RRAS server to the VPN client.&lt;/p&gt;  &lt;p&gt;The advantage in this scenario compared to multiple NIC case is not by saving the cost of NIC, but on having single IP subnet behind your NAT router. This single IP subnet will be used by your LAN machines (say file server) as well as RRAS server and its connected remote access clients. . The advantage in this scenario is as RRAS server supports proxy ARP functionality, LAN clients &lt;i&gt;automatically detects&lt;/i&gt; they need to send packets via RRAS server when trying to send packets to VPN clients – without any extra IP routes. And LAN clients or remote access clients can access Internet via your existing NAT router – thereby simplifying the deployment.&lt;/p&gt;  &lt;h4&gt;5.4&lt;a title="_Toc222565989" name="_Toc222565989"&gt;&lt;/a&gt; Load Balancing and High availability&lt;/h4&gt;  &lt;p&gt;With increased number of mobile users and telecommuters, 24x7 remote access service has becomes life-line to organizations and this mandates a need for high availability VPN server solution. Windows based RRAS server supports high availability using multiple options:&lt;/p&gt;  &lt;h6&gt;5.4&lt;a title="_Toc222565990" name="_Toc222565990"&gt;&lt;/a&gt;.1 DNS Round robin&lt;/h6&gt;  &lt;p&gt;DNS Round Robin mechanism on DNS server enables – multiple servers to be registered with the same hostname but having different IP addresses. This way you can deploy a pool of VPN servers at the edge of your network with same server name (e.g. myvpnserver.contoso.com) which can be configured as destination VPN Server in the VPN client configuration. Whenever a VPN client tries to establish the VPN tunnel, it does a name look-up and gets the IP address list from the DNS server. And client picks the first one and establishes the VPN tunnel. The DNS server sends this list differently on each DNS query in a round-robin manner – thereby load balancing each VPN connection to a different server.&lt;/p&gt;  &lt;p&gt;This mechanism works for all VPN tunnels and requires no changes on VPN server. &lt;/p&gt;  &lt;p&gt;However, this mechanism has some limitations:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;It doesn’t take into consideration usage metrics of a given server – thereby may yield to different load on each server. &lt;/li&gt;    &lt;li&gt;Whenever a VPN server goes down, the DNS records in the DNS server need to be “manually” updated to reflect the change. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;Note&lt;/b&gt;: For the VPN tunnels that requires machine certificate to be installed on the VPN server i.e. L2TP/IPSec, SSTP, IKEv2 – the subject name of the machine certificate MUST match the name given in DNS server (e.g. myvpnserver.contoso.com) and not the real machine name of the VPN Server. This is because the VPN client does the subject name validation of the machine certificate sent by VPN server against the name with which it connects – and this validation will fail otherwise.&lt;/p&gt;  &lt;h6&gt;5.4.2&lt;a title="_Toc222565991" name="_Toc222565991"&gt;&lt;/a&gt; Network Load Balancing&lt;/h6&gt;  &lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb742455.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb742455.aspx"&gt;Network load balancing service&lt;/a&gt; (NLBS) inside Windows server is the implementation of stateless load balancing to provide high availability and scalability to different server roles. One advantage of using NLBS is that all the servers in a cluster monitor each other with a heartbeat signal, so there is no single point of failure.&lt;/p&gt;  &lt;p&gt;For further details, refer to &lt;a href="http://blogs.technet.com/rrasblog/archive/2006/02/16/419712.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2006/02/16/419712.aspx"&gt;this&lt;/a&gt; article.&lt;/p&gt;  &lt;h6&gt;5.4.3 &lt;a title="_Toc222565992" name="_Toc222565992"&gt;&lt;/a&gt;SSL Load Balancers (only for SSTP)&lt;/h6&gt;  &lt;p&gt;SSTP based VPN tunnel uses standard HTTPS protocol and hence traditional SSL load balancers (e.g. F5 BIGIP) can be used to terminate HTTPS connections coming from SSTP configured VPN clients and load balance it by sending each VPN connection to different RRAS based VPN servers. &lt;/p&gt;  &lt;p&gt;Advantage of this approach:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;SSL load balancers terminates SSL and only sends HTTP packets to VPN server – thereby removing the encryption/decryption load from the VPN server. &lt;/li&gt;    &lt;li&gt;SSL load balancers are stateful in nature and keep track of the HTTPS sessions passing through it. This way a VPN server going down is discovered by load balancer which then removes that VPN server from its pool. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Note: This scenario requires RRAS server to be configured to accept HTTP connections listening on TCP port 80. The machine certificate required for SSTP connections is installed on SSL load balancer. And its certificate hash (or thumbprint) of this machine certificate needs to be configured on RRAS server for SSTP connections to succeed (this is an additional security cover). For further details, please follow &lt;a href="http://blogs.technet.com/rrasblog/archive/2007/03/07/configuring-sstp-in-a-reverse-proxy-scenario.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2007/03/07/configuring-sstp-in-a-reverse-proxy-scenario.aspx"&gt;this&lt;/a&gt; article.&lt;/p&gt;  &lt;h4&gt;5.5 Further Readings&lt;/h4&gt;  &lt;p&gt;Here are the references to other relevant posts&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx"&gt;Remote Access Design Guidelines – Part 1: Overview&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx"&gt;Remote Access Design Guidelines – Part 2: VPN Client Software Selection&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx"&gt;Remote Access Design Guidelines – Part 3: Tunnel Selection, Authentication, Authorization and Accounting&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx"&gt;Remote Access Design Guidelines – Part 4: IP Routing and DNS&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-1-configuring-remote-access-clients.aspx"&gt;Remote Access Deployment – Part 1: Configuring Remote Access Clients&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx"&gt;Remote Access Deployment – Part 2: Configuring RRAS as a VPN server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-3-configuring-radius-server-for-remote-access.aspx"&gt;Remote Access Deployment – Part 3: Configuring RADIUS Server for remote access&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3213937" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Remote Access Design Guidelines – Part 4: IP Routing and DNS</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx</link><pubDate>Tue, 17 Mar 2009 14:36:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3213930</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3213930</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In this post, I will walk through some aspects on IP addressing, routing and name resolution related design guidelines.&lt;/p&gt;  &lt;h5&gt;&lt;a title="_Toc224633150" name="_Toc224633150"&gt;&lt;/a&gt;4.&lt;a title="_Toc222565974" name="_Toc222565974"&gt;&lt;/a&gt;1 IP Addressing&lt;/h5&gt;  &lt;p&gt;The VPN client machine will have minimum two IP addresses – one that it gets from ISP through which it connects to VPN server (called as outer or internet IP address) and other is the one it gets from VPN server through which it connects to machines behind VPN server (called as inner or intranet IP address). And each of these addresses can be IPv4 or IPv6 or both.&lt;/p&gt;  &lt;p&gt;All tunnels are supported over IPv4 &lt;b&gt;Internet&lt;/b&gt;. However please note that L2TP/IPSec, SSTP and IKEv2 tunnels are supported over IPv6 internet and PPTP cannot be used in this scenario.&lt;/p&gt;  &lt;p&gt;Both IPv4 as well as IPv6 addresses can be sent to VPN client by VPN server – for all tunnels. This way the VPN client machines can access IPv4 as well as IPv6 resources of &lt;b&gt;Intranet&lt;/b&gt;. RRAS server can be configured in following ways - with an IP address pool that it will use to hand-out the (inner) IP address to the VPN clients:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;If handing out IPv4 address to the VPN client&lt;/b&gt;: IPv4 pool can be statically configured on the RRAS server using MMC, netsh OR it can be dynamically obtained from a DHCP server located on intranet interface of RRAS server. This address is passed to VPN client during PPP IP configuration (i.e. IPCP) stage or IKEv2 configuration payload stage. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;For example, we have a RRAS server with two network interfaces – one towards internet (100.100.100.1/24) and one towards intranet (192.168.1.1/24). In this scenario, there are two options for VPN clients’ IP address pool: -&lt;/p&gt;  &lt;p&gt;Option a) VPN client gets the IP address &lt;i&gt;from the same intranet pool&lt;/i&gt; (i.e. 192.168.1.0/24). This scenario is common in small-medium businesses – as one IP subnet is sufficient for LAN as well as remote access clients. In this scenario – care must be taken to restrict the pool to appropriate IP addresses if statically configured on RRAS server – otherwise you may land into situations where same IP address is allocated to VPN client by RRAS server as well as a LAN client by the DHCP server. The advantage in this scenario is as RRAS server supports proxy ARP functionality, LAN clients &lt;i&gt;automatically detects&lt;/i&gt; they need to send packets via RRAS server when trying to send packets to VPN clients. And you don’t need to configure any additional routes.&lt;/p&gt;  &lt;p&gt;Option b) VPN client gets the IP address &lt;i&gt;from a different pool&lt;/i&gt; which is not same as intranet interface (say 192.168.2.0/24). This is common in big organizations having large number of machines and subnets. In this scenario – you must ensure appropriate IP routing is done for this subnet on the LAN side i.e. LAN clients must be able to reach to the subnet which VPN clients belongs to (i.e. 192.168.2.0 in this example).&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;If handing out IPv6 address to the VPN client&lt;/b&gt;: IPv6 pool can be statically configured on the RRAS server with a prefix length of 64 (e.g. 3000:1:1:2:: ). This prefix has to be different compared to RRAS server intranet interface. This prefix is passed to VPN client via IPv6 router advertisement once the PPP interface comes up or IKEv2 configuration payload stage. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;For example, we have a RRAS server with two network interfaces – one towards internet (100.100.100.1/24) and one towards intranet (3000:1:1:1::/64). In this example, the IPv6 address pool for VPN client cannot be same as 3000:1:1:1::/64 and it has to be a different pool (say 3000:1:1:2:: ). You must ensure appropriate IPv6 routing is done for this prefix on the LAN side i.e. LAN clients must be able to reach to the prefix which VPN client belongs to (i.e. 3000:1:1:2::/64 for this example).&lt;/p&gt;  &lt;h5&gt;4.2 &lt;a title="_Toc222565977" name="_Toc222565977"&gt;&lt;/a&gt;Name resolution&lt;/h5&gt;  &lt;p&gt;The intranet resources can be accessed by VPN clients using names (e.g. &lt;a href="http://team/mysite" mce_href="http://team/mysite"&gt;http://team/mysite&lt;/a&gt;). And names can be resolved to IP address using DNS based resolution (IPv4 as well as IPv6), WINS based resolution (only IPv4) and NetBIOS based broadcast resolution (only IPv4).&lt;/p&gt;  &lt;p&gt;WINS and DNS based name resolution requires a server address to be provisioned on the VPN client. The WINS server can run on top of IPv4 based network only, whereas DNS server can have IPv4 as well as IPv6 address – or in other words VPN client can reach the DNS server over IPv4 or IPv6 based network. &lt;/p&gt;  &lt;p&gt;The IP address of WINS and DNS server is provisioned on VPN client in one of the following ways:&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;Statically configured&lt;/b&gt; inside VPN client configuration – inside Network Properties of VPN client.&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;Dynamically obtained&lt;/b&gt; from the VPN server – during connection establishment. This handshake process varies between PPP based tunnels (aka PPTP, L2TP and SSTP) and IKEv2 based tunnel (aka VPN reconnect). &lt;/p&gt;  &lt;p&gt;For PPP based tunnel, the WINS and DNS server’s IPv4 address picked up from VPN server’s private interface is passed via PPP IPv4 configuration stage (called as IPCP) to the VPN client. And the DNS server’s IPv6 address is passed via DHCPv6 Inform transaction after IPv6 prefix is assigned to VPN client via router advertisements. &lt;b&gt;Note&lt;/b&gt;: This requires VPN server to be running DHCPv6 relay agent and DHCPv6 stateless server running on the network behind VPN server.&lt;/p&gt;  &lt;p&gt;For IKEv2 based tunnel, the WINS and DNS server’s IPv4 as well as IPv6 address is picked up from VPN server’s private interface and is passed via IKEv2 tunnel establishment phase. &lt;/p&gt;  &lt;p&gt;The NetBIOS based name resolution for IPv4 resources works as a broadcast – i.e. doesn’t require any server to be provisioned. It requires “Enable broadcast name resolution” to be enabled on RRAS based VPN server and “Enable NetBIOS over TCP/IP” setting to be enabled on VPN client.&lt;/p&gt;  &lt;h5&gt;4.3 &lt;a title="_Toc224633152" name="_Toc224633152"&gt;&lt;/a&gt;Routing on VPN Client side&lt;/h5&gt;  &lt;p&gt;Once the VPN interface comes up, VPN client machine has two IP interfaces – one is the VPN interface and second is the internet interface on top of which the VPN connection is established.&lt;/p&gt;  &lt;p&gt;Every TCP/IP packet goes through a route look-up to find the best matching route (longest prefix match) for the given destination. And for most practical cases, most of the resources don’t match a specific route and thereby matches the default route (i.e. routing table entry with destination as 0.0.0.0 for IPv4 and ::/0 for IPv6). &lt;/p&gt;  &lt;p&gt;There are two choices for the “default route” on the VPN client machine:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Default route over VPN interface&lt;/b&gt;: This means all the traffic (intranet as well as internet) will flow on top of VPN interface from client to server – except the local subnet traffic flowing over underlying internet interface. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;To enable this scenario&lt;/b&gt;,&lt;b&gt; &lt;/b&gt;“use default gateway” should be enabled inside IPv4 and IPv6 properties of VPN client configuration. &lt;/p&gt;  &lt;p&gt;For example, the client machine has a LAN interface providing Internet connectivity with IP Address as 192.168.1.2 with default IPv4 route to a broadband router running NAT with IP address 192.168.1.1. On the LAN side, there is a printer too with IP address 192.168.1.3. &lt;/p&gt;  &lt;p&gt;Once the VPN connection is successfully established, the client machine has a VPN interface with IP address as 10.0.0.100 with VPN server tunneled address as 10.0.0.1. And one more default IP route is added on the client machine “with lowest metric” (or in other words highest preference) – with gateway address as 10.0.0.1. Same thing happens if IPv6 prefix is assigned to the VPN client.&lt;/p&gt;  &lt;p&gt;Whenever the client machine access any machines on the LAN side (i.e. 192.168.1.0/24), those IP packets goes directly over LAN without going over VPN tunnel. However, when the client machine accesses any resources behind RRAS server (i.e. intranet resources) or machines on the internet side (say http://www.microsoft.com), those packets traverses the VPN tunnel and reach the VPN server. And the VPN server based upon the destination routes the packet onto Internet or to Intranet side. &lt;b&gt;Note: &lt;/b&gt;If private IPv4 address is given to VPN client, then NAT should be running on RRAS server or some machine in-front of RRAS server (i.e. between RRAS server and internet) to translate the private IP to public IP.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Note&lt;/b&gt;: This scenario requires &lt;b&gt;DNS server on intranet side&lt;/b&gt; to resolve Intranet as well as Internet queries. And it is assumed that local subnet traffic is resolved via some broadcast resolution (like NetBIOS for IPv4 and LLMNR for IPv6).&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Default route over internet interface&lt;/b&gt;: This means only intranet traffic traverses the VPN tunnel and rest of all traffic (i.e. local subnet traffic OR Internet traffic) goes over underlying internet interface. This scenario is also called as “&lt;b&gt;split-tunneling&lt;/b&gt;”. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;b&gt;To enable this scenario&lt;/b&gt;,&lt;b&gt; &lt;/b&gt;“use default gateway” should be disabled inside IPv4 and IPv6 properties of VPN client configuration.&lt;/p&gt;  &lt;p&gt;If we take the above example, once the VPN connection is successfully established, the default route remains untouched (i.e. continue to point to the underlying internet interface). &lt;/p&gt;  &lt;p&gt;The VPN client can access the intranet machines which falls under the IPv4 subnet (i.e. 10.0.0.0/8) or IPv6 prefix that the client receives from the VPN Server. This may be well suited for small deployment (i.e. having one subnet or prefix range), however in case the intranet resources are divided into multiple subnets or prefixes, then that entire range needs to be provisioned on the VPN client using some mechanism (like using connection manager administration kit aka CMAK).&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Note&lt;/b&gt;: This scenario requires &lt;b&gt;DNS server on intranet side&lt;/b&gt; to resolve Intranet as well as Internet queries – as DNS queries may still go over VPN interface. And it is assumed that local subnet traffic is resolved via some broadcast resolution (like NetBIOS for IPv4 and LLMNR for IPv6).&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Warning&lt;/b&gt;: As a security note, &lt;b&gt;Internet connection sharing MUST be disabled&lt;/b&gt; &lt;b&gt;on the VPN client machine&lt;/b&gt; – to prevent other users (behind VPN client machine or may be on Internet) to access the corpnet using the VPN client machine’s tunnel to the VPN server.&lt;/p&gt;  &lt;h4&gt;4.4 Further Readings&lt;/h4&gt;  &lt;p&gt;Here are the references to other relevant posts&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx"&gt;Remote Access Design Guidelines – Part 1: Overview&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx"&gt;Remote Access Design Guidelines – Part 2: VPN Client Software Selection&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx"&gt;Remote Access Design Guidelines – Part 3: Tunnel Selection, Authentication, Authorization and Accounting&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx"&gt;Remote Access Design Guidelines – Part 5: Where to place RRAS server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3213930" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Remote Access Design Guidelines – Part 3: Tunnel selection, Authentication, Authorization and Accounting</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx</link><pubDate>Tue, 17 Mar 2009 14:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3213924</guid><dc:creator>rrasblog</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3213924</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In this post, I will walk through the most important topic – which authentication protocol, VPN tunnel to use, how to authorize access of your VPN users.&lt;/p&gt;  &lt;p&gt;Lets have a look:&lt;/p&gt;  &lt;h5&gt;&lt;a title="_Toc224633143" name="_Toc224633143"&gt;&lt;/a&gt;3.&lt;a title="_Toc222565979" name="_Toc222565979"&gt;&lt;/a&gt;1 User Authentication&lt;/h5&gt;  &lt;p&gt;The remote access user is authenticated by the VPN server during VPN tunnel establishment phase. &lt;/p&gt;  &lt;p&gt;The following table highlights the various &lt;strong&gt;recommended &lt;/strong&gt;deployment options for user authentication. It highlights the deployment requirements for a given authentication protocol on the client side as well as the network side (RRAS server, Radius server end) - going down from highest security level to lowest level&lt;/p&gt;  &lt;p&gt;To enable user authentication, RRAS server to be configured for Radius based authentication and Radius server is joined to Active directory domain in order to authenticate users. The Radius server itself may be running on the same server as RRAS or on a different server.&lt;/p&gt;  &lt;p&gt;   &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td valign="top" width="234"&gt;           &lt;p&gt;&lt;b&gt;Authentication Protocol**&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="234"&gt;           &lt;p&gt;&lt;b&gt;VPN Client&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="284"&gt;           &lt;p&gt;&lt;b&gt;Network Side&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="234"&gt;           &lt;p&gt;PEAP with inner method as EAP-smartcard&lt;/p&gt;            &lt;p&gt;EAP-smartcard&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="234"&gt;           &lt;p&gt;Smart-Card is populated with relevant user certificate and root certificate&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="284"&gt;           &lt;p&gt;Radius server is joined to domain, deployed with relevant machine certificate and the root certificate&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="234"&gt;           &lt;p&gt;PEAP with inner method as EAP-TLS (certificate on this computer)&lt;/p&gt;            &lt;p&gt;EAP-TLS (certificate on this computer)&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="234"&gt;           &lt;p&gt;User certificate store is populated with relevant certificate in “Personal” store and root certificate in “trusted root CA” store&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="284"&gt;           &lt;p&gt;Radius server is joined to domain, deployed with relevant machine certificate and root certificate&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="234"&gt;           &lt;p&gt;PEAP with EAP-MSCHAPv2&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="234"&gt;           &lt;p&gt;User or Machine certificate store is populated with root certificate in “trusted root CA” store. &lt;/p&gt;            &lt;p&gt;VPN client is configured with username/password&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="284"&gt;           &lt;p&gt;Radius server is deployed with relevant machine certificate and root certificate&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="234"&gt;           &lt;p&gt;EAP-MSCHAPv2&lt;/p&gt;            &lt;p&gt;MSCHAPv2&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="234"&gt;           &lt;p&gt;VPN client configured with username/password&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="284"&gt;           &lt;p&gt;Radius server requires no certificate in this scenario.&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/p&gt;  &lt;p&gt;** &lt;b&gt;The same authentication protocol must be configured on both ends of authentication i.e. VPN client as well as Radius server. &lt;/b&gt;Within Radius server, a policy should be created for NAS type as RRAS server. And within this policy, &lt;b&gt;the&lt;/b&gt; &lt;b&gt;specific authentication protocols must be configured inside policy “condition”&lt;/b&gt;. Additionally &lt;b&gt;RRAS server must be configured&lt;/b&gt; to accept the specific authentication protocol.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Note: &lt;/b&gt;The above table doesn’t include certain third party EAP methods (like &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=2466F0E3-231B-46B5-AE1E-0E5D3C3CACAD&amp;amp;DisplayLang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=2466F0E3-231B-46B5-AE1E-0E5D3C3CACAD&amp;amp;DisplayLang=en"&gt;RSA SecurID&lt;/a&gt;) also supported by RAS based remote access solution. &lt;/p&gt;  &lt;h5&gt;3.2 Tunnel Types&lt;/h5&gt;  &lt;p&gt;There are different VPN tunnels that exist inside Windows OS. First, let us compare the different tunnels on general and network centric parameters&lt;/p&gt;  &lt;p&gt;   &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td valign="top" width="129"&gt;           &lt;p&gt;&lt;b&gt;Tunnel Type&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;&lt;b&gt;OS support&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="91"&gt;           &lt;p&gt;&lt;b&gt;Scenario&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="250"&gt;           &lt;p&gt;&lt;b&gt;IP Addressing&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;&lt;b&gt;Traversal&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;&lt;b&gt;Mobility&lt;/b&gt;&lt;/p&gt;            &lt;p&gt;&lt;b&gt;Enabled&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="129"&gt;           &lt;p&gt;&lt;b&gt;PPTP&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;XP, 2003, Vista, WS08, W7, WS08 R2&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="91"&gt;           &lt;p&gt;Remote Access&lt;/p&gt;            &lt;p&gt;Site-to-Site&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="250"&gt;           &lt;p&gt;Works over IPv4 based Internet&lt;/p&gt;            &lt;p&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;NAT via PPTP enabled NAT devices&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;No&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="129"&gt;           &lt;p&gt;&lt;b&gt;L2TP/IPSec&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;XP, 2003, Vista, WS08, W7, WS08 R2&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="91"&gt;           &lt;p&gt;Remote Access&lt;/p&gt;            &lt;p&gt;Site-to-Site&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="250"&gt;           &lt;p&gt;Works over IPv4 as well as IPv6 based Internet&lt;/p&gt;            &lt;p&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;NAT if configured for NAT-T&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;No&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="129"&gt;           &lt;p&gt;&lt;b&gt;SSTP&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;Vista SP1, WS08, W7, WS08 R2&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="91"&gt;           &lt;p&gt;Remote Access&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="250"&gt;           &lt;p&gt;Works over IPv4 as well as IPv6 based Internet&lt;/p&gt;            &lt;p&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;NAT,&lt;/p&gt;            &lt;p&gt;Firewalls,&lt;/p&gt;            &lt;p&gt;Web Proxy (as it uses TCP port 443) &lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;No&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="129"&gt;           &lt;p&gt;&lt;b&gt;IKEv2 (VPN Reconnect)&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;W7, WS08 R2&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="91"&gt;           &lt;p&gt;Remote Access&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="250"&gt;           &lt;p&gt;Works over IPv4 as well as IPv6 based Internet&lt;/p&gt;            &lt;p&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;NAT if configured for NAT-T&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="106"&gt;           &lt;p&gt;Yes&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/p&gt;  &lt;p&gt;Now let us compare these VPN tunnels on the various security related parameters:&amp;#160; &lt;/p&gt;  &lt;p&gt;   &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td valign="top" width="123"&gt;           &lt;p&gt;&lt;b&gt;Tunnel Type&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="158"&gt;           &lt;p&gt;&lt;b&gt;Authentication&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="165"&gt;           &lt;p&gt;&lt;b&gt;VPN Client&lt;/b&gt;&lt;/p&gt;            &lt;p&gt;&lt;b&gt;Requirement****&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="197"&gt;           &lt;p&gt;&lt;b&gt;Network Side Requirement****&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="155"&gt;           &lt;p&gt;&lt;b&gt;Data Confidentiality&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="123"&gt;           &lt;p&gt;&lt;b&gt;PPTP&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="158"&gt;           &lt;p&gt;User authentication via PPP*&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="165"&gt;           &lt;p&gt;None &lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="197"&gt;           &lt;p&gt;None&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="155"&gt;           &lt;p&gt;RC4&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="123"&gt;           &lt;p&gt;&lt;b&gt;L2TP/IPSec&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="158"&gt;           &lt;p&gt;Machine authentication via IPSec &lt;b&gt;&lt;i&gt;and**&lt;/i&gt;&lt;/b&gt; user authentication via PPP&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="165"&gt;           &lt;p&gt;Machine certificate store must be populated with the machine certificate in “Personal” store and the root certificate in “trusted root CA” store&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="197"&gt;           &lt;p&gt;RRAS server is deployed with machine certificate and the root certificate&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="155"&gt;           &lt;p&gt;DES, 3DES, AES&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="123"&gt;           &lt;p&gt;&lt;b&gt;SSTP&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="158"&gt;           &lt;p&gt;User authentication via PPP*&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="165"&gt;           &lt;p&gt;Machine certificate store must be populated with the root certificate in “trusted root CA” store.&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="197"&gt;           &lt;p&gt;RRAS server is deployed with the machine certificate and the root certificate&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="155"&gt;           &lt;p&gt;RC4, AES&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="123"&gt;           &lt;p&gt;&lt;b&gt;IKEv2 (VPN Reconnect)&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="158"&gt;           &lt;p&gt;User authentication via IKEv2***&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="165"&gt;           &lt;p&gt;Machine certificate store must be populated with the root certificate in “trusted root CA” store.&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="197"&gt;           &lt;p&gt;RRAS server is deployed with the machine certificate and the root certificate&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="155"&gt;           &lt;p&gt;3DES, AES&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td valign="top" width="123"&gt;           &lt;p&gt;&lt;b&gt;IKEv2 (VPN Reconnect)&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="158"&gt;           &lt;p&gt;Machine authentication via IKEv2***&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="165"&gt;           &lt;p&gt;Machine certificate store must be populated with relevant machine certificate in “Personal” store and the root certificate in “trusted root CA” store&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="197"&gt;           &lt;p&gt;RRAS server is deployed with the machine certificate and the root certificate&lt;/p&gt;         &lt;/td&gt;          &lt;td valign="top" width="155"&gt;           &lt;p&gt;3DES, AES&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/p&gt;  &lt;p&gt;Where,&lt;/p&gt;  &lt;p&gt;* PPTP, SSTP tunnel does PPP based &lt;i&gt;user authentication &lt;/i&gt;(password or certificate based as explained in earlier section including EAP as well as non-EAP based authentication protocols).&lt;/p&gt;  &lt;p&gt;** L2TP/IPSec tunnel first does IPSec level machine authentication (pre-shared key or certificate based) followed by PPP based user authentication (password or certificate based as explained in earlier section – including EAP as well as non-EAP based authentication protocols). The machine authentication is done between VPN client and RRAS server, whereas user authentication is performed between VPN client and Radius server.&lt;/p&gt;  &lt;p&gt;*** VPN reconnect (IKEv2) tunnel supports &lt;i&gt;machine authentication&lt;/i&gt; (certificate only) or &lt;i&gt;user authentication &lt;/i&gt;(only EAP based authentication using password or certificate based authentication as given in earlier section). The machine authentication is done between VPN client and RRAS server, whereas user authentication is performed between VPN client and Radius server.&lt;/p&gt;  &lt;p&gt;**** The certificate requirements on the VPN client side or on the network side are additional to the authentication requirements that are described in user authentication section above. The certificates mentioned here are required for initial part of tunnel (like IPSec session for L2TP scenario or SSL session for SSTP scenario) to come up before performing user authentication. Please note: this &lt;b&gt;doesn’t mean this requires separate set of certificates&lt;/b&gt; need to be managed for initial part of tunnel and subsequent user authentication (e.g. if PEAP is used with SSTP, then the root certificate on the client side for PEAP can be same as root certificate for SSL negotiation) – thereby easing out deployment. However, if RRAS server and Radius server are deployed on different machines, then different machine certificates are required - one on the RRAS server side (for L2TP/IPSec or IKEv2 or SSTP) for the initial part of tunnel negotiation and other on the Radius server side (for PEAP or EAP-TLS authentication). However the client side certificate remains the same.&lt;/p&gt;  &lt;h5&gt;3.3 Tunnel Selection&lt;/h5&gt;  &lt;p&gt;As described in the above section, there are different types of VPN tunnels that is supported by Windows based VPN client and server. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;RECOMMENDATION:&lt;/strong&gt; Based upon the feature set, our recommended tunnel types are IKEv2 followed by SSTP. &lt;/p&gt;  &lt;p&gt;As a network admin, your main goal is to enable smooth migration of your existing PPTP or L2TP/IPSec users to IKEv2 followed by SSTP based deployment. But that requires each remote access user to change their operating system – which may not be possible at once. This means multiple tunnel types needs to be supported on the server side during the migration timeframe. This is where you can leverage the &lt;b&gt;VPN tunnel strategy&lt;/b&gt; feature inside Windows VPN client that helps you specify the order in which VPN tunnels are tried – till a given tunnel type is able to successfully connect to the VPN server. &lt;/p&gt;  &lt;p&gt;For further details, please read &lt;a href="http://blogs.technet.com/rrasblog/archive/2009/02/11/vpn-tunnel-strategy-defining-the-connection-order-between-various-tunnel-types.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/02/11/vpn-tunnel-strategy-defining-the-connection-order-between-various-tunnel-types.aspx"&gt;this&lt;/a&gt; blog.&lt;/p&gt;  &lt;h5&gt;3.4 &lt;a title="_Toc224633146" name="_Toc224633146"&gt;&lt;/a&gt;Authorization&lt;/h5&gt;  &lt;p&gt;Authentication (as given above) allows a remote access user to identify itself to the remote access server and the remote access server verifying the user identity. Whereas, authorization that is done after the user authentication allows admin to specify what the remote access user can access. Some examples of authorization policies are: allow user to access specific IP subnets, allow VPN access during particular time of the day, allow access with x minute idle timeout, etc. &lt;/p&gt;  &lt;p&gt;To enable user authorization, &lt;b&gt;RRAS must be configured to use Radius based authorization provider&lt;/b&gt;. And on the Radius server side, within the authentication policy &lt;b&gt;different authorization rules can be added as “constraints”&lt;/b&gt;. If there are multiple constraints, the authenticated VPN connection will be subjected (or enforced) to each of those constraints.&lt;/p&gt;  &lt;h5&gt;3.5&lt;a title="_Toc222565982" name="_Toc222565982"&gt;&lt;/a&gt; Accounting&lt;/h5&gt;  &lt;p&gt;The activities of the remote access users can be accounted using Radius based accounting. These activity logs include username, session start time, session end time, transmit/receive bytes and transmit/receive packets.&lt;/p&gt;  &lt;p&gt;To enable user accounting, &lt;b&gt;RRAS must be configured to use Radius based accounting provider&lt;/b&gt;. The Radius server must be configured to log accounting information in a file OR inside a database.&lt;/p&gt;  &lt;h5&gt;3.6 &lt;a title="_Toc222565983" name="_Toc222565983"&gt;&lt;/a&gt;Health check&lt;/h5&gt;  &lt;p&gt;RRAS Server allows Network Access Protection (NAP) based health check (AUTHORIZATION) of the remote VPN users before they are granted access to the intranet. The health definition can be: checking VPN client machine running firewall and antivirus, enabled for Windows update, is running latest patches etc. &lt;/p&gt;  &lt;p&gt;To enable VPN NAP deployment, &lt;b&gt;VPN client and the Radius server policy must be configured for PEAP as authentication&lt;/b&gt; &lt;b&gt;protocol with NAP quarantine check enabled inside PEAP configuration&lt;/b&gt;. Why only PEAP. This is because the client PC’s health information is relayed from the VPN client to the Radius server inside PEAP protocol and hence no other authentication protocols can be used. And within PEAP, any inner EAP method like EAP-MSCHAPv2 or EAP-Smartcard or user certificate can be used. This can also include other 3&lt;sup&gt;rd&lt;/sup&gt; party EAP methods like one-time password that plugs into RAS EAP framework. VPN NAP is supported for all VPN tunnel types i.e. PPTP, L2TP/IPSec, SSTP and IKEv2.&lt;/p&gt;  &lt;p&gt;Radius server must be enabled for NAP based deployment. This includes creating of remote access policies for healthy as well as unhealthy clients and creating the appropriate connection request policy. &lt;/p&gt;  &lt;p&gt;To restrict unhealthy clients to a quarantine zone hosting remediation servers (like antivirus signature server, patch update server), &lt;b&gt;remediation server group &lt;/b&gt;must be created inside Radius server. Remediation server group allows you to specify the IPv4 and/or IPv6 address of the remediation servers. This list will be sent by Radius server to the RRAS server once it determines the VPN client is unhealthy and RRAS server applies this list as IP filters on that particular VPN sub-interface - means “allow packets to/from these IP addresses and drop rest”. Once the client becomes healthy, Radius server informs RRAS server which removes these filters from that particular VPN sub-interface. And if there are any other IP filters that are sent for the VPN interface (which have been added as “IP Filters” of remote access policy representing healthy clients), they will be applied. &lt;/p&gt;  &lt;p&gt;To reiterate, &lt;b&gt;remediation server group&lt;/b&gt; and the &lt;b&gt;IP Filters&lt;/b&gt; configured inside given remote access policy have separate meanings on RRAS server. The former (i.e. remediation group) are used explicitly for NAP i.e. gets applied on specific VPN sub-interface on RRAS server when the VPN client is unhealthy and removed when the VPN client becomes healthy. However the later ones (i.e. IP filters) are added to VPN client even if NAP is not enabled OR applied when NAP is enabled but the VPN client has become healthy.&lt;/p&gt;  &lt;h4&gt;3.7 Further Readings&lt;/h4&gt;  &lt;p&gt;Here are the references to other relevant posts&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx"&gt;Remote Access Design Guidelines – Part 1: Overview&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx"&gt;Remote Access Design Guidelines – Part 2: VPN Client Software Selection&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx"&gt;Remote Access Design Guidelines – Part 4: IP Routing and DNS&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx"&gt;Remote Access Design Guidelines – Part 5: Where to place RRAS server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3213924" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Remote Access Design Guidelines – Part 2: VPN client software selection</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx</link><pubDate>Tue, 17 Mar 2009 14:14:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3213915</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3213915</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In this post, I will walk through the different ways in which you can enable VPN functionality on the remote access devices (desktops, laptops used by your remote access users). &lt;/p&gt;  &lt;p&gt;Lets look at the various choices:&lt;/p&gt;  &lt;h4&gt;2.1 Operating Systems&lt;/h4&gt;  &lt;p&gt;The remote access users in your organization will normally be running different operating systems on their remote access devices (like PCs and laptops). The choice of operating system governs few important decisions regarding remote access deployment - mainly the VPN tunnel selection and the authentication protocol selection – as defined further in next few posts.&lt;/p&gt;  &lt;h4&gt;2.2 VPN Client Selection&lt;/h4&gt;  &lt;p&gt;There are three types of VPN client software that runs on Windows OS &lt;b&gt;using&lt;/b&gt; &lt;b&gt;Windows VPN stack&lt;/b&gt; (i.e. PPTP, L2TP, SSTP or IKEv2 VPN tunnel):&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;In-built (or in-the-box) VPN client - created by end user using “Setup a connection or network” wizard inside “Network and Sharing Center” in Vista/Windows7. &lt;/li&gt;    &lt;li&gt;Connection Manager (CM) client created using Connection Manager Administration Kit (CMAK) software on the RRAS server. A CM client is created by the remote access server administrator and then shared to the end users via email or file/web server. &lt;/li&gt;    &lt;li&gt;3&lt;sup&gt;rd&lt;/sup&gt; party VPN client software that has its own provisioning mechanism and user interface - however runs&lt;sup&gt;**&lt;/sup&gt; on top of the VPN stack of Windows OS. These clients can connect to Windows based RRAS servers or their own 3&lt;sup&gt;rd&lt;/sup&gt; party VPN servers. The functionality exposed by this type of VPN client varies from vendor to vendor and hence is kept outside the scope of this post. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;** Please note: There are a lot of 3&lt;sup&gt;rd&lt;/sup&gt; party VPN clients which works on top of Windows OS but uses its own VPN client stack (like IPSEC X Auth based, SSL network connector driven) instead of Windows VPN stack. Hence all these clients are kept outside the scope of this post.&lt;/p&gt;  &lt;p&gt;The following table summarizes the feature set between in-built VPN client and connection manager VPN client: &lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;&lt;b&gt;Feature&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;&lt;b&gt;In-Built VPN client&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;&lt;b&gt;CM VPN client&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;Creation&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;On the client device – using ``Network and Sharing Center” – usually done by end users&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;On network side – using CMAK tool – usually done by administrators&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;Change&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;Entire configuration can be changed by end user – using VPN client ``Properties”&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;Minimal configuration change possible by end user – using CM.&lt;/p&gt;          &lt;p&gt;However administrator can change the profile – using CMAK and then send back to end users&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;IPV4, IPV6 Support&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;Both&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;Both&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;Authentication &amp;amp; Tunnel Selection&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;All&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;All – though tunnel selection order is fine-grained in CMAK – with additional options of PPTP first, L2TP first and SSTP first.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;NAP Support&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;Supported&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;Supported&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;Multiple VPN servers&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;Partially allowed – only one host name*** or IP address of VPN server can be configured. &lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;Allows a list of VPN servers to be provisioned and end user can select one from the drop-down&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;IP Routes &lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;Ability to select default route addition on client machine after VPN interface comes up &lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;Allows a list of IP routes (including default route) to be provisioned on client machine after VPN interface comes up&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;Web Proxy Address &lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;Not allowed – user need to explicitly configure intranet web proxy address inside IE for the VPN interface&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;Allows web proxy address to be provisioned inside CM package. This will be configured inside IE after VPN interface comes up&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="139"&gt;         &lt;p&gt;Customization&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="393"&gt;         &lt;p&gt;Not allowed&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="266"&gt;         &lt;p&gt;Allows icons, help message text, pre connect and post connect code to be added to the VPN package&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;*** A DNS name can represent a set of VPN servers if deployed using DNS round-robin as discussed in a subsequent section. Hence the in-built VPN client does support multiple VPN servers using single hostname. And CM based client goes one step further allowing a list of VPN server names/IP address to be provisioned by admin of which end user can select one of them using CM client properties. However please note: in case of failure of connectivity to one server, the CM client doesn’t fallback or tries the next one.&lt;/p&gt;  &lt;h4&gt;&lt;/h4&gt;  &lt;h4&gt;2.3 Further Readings&lt;/h4&gt;  &lt;p&gt;Here are the references to other relevant posts&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx"&gt;Remote Access Design Guidelines – Part 1: Overview&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx"&gt;Remote Access Design Guidelines – Part 3: Tunnel selection, Authentication, Authorization and Accounting&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx"&gt;Remote Access Design Guidelines – Part 4: IP Routing and DNS&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx"&gt;Remote Access Design Guidelines – Part 5: Where to place RRAS server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3213915" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Remote Access Design Guidelines – Part 1: Overview</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx</link><pubDate>Tue, 17 Mar 2009 14:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3213907</guid><dc:creator>rrasblog</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3213907</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-1.aspx#comments</comments><description>&lt;p&gt;Hello Customers,&lt;/p&gt;  &lt;p&gt;In last few releases, we have added plenty of “cool” features in RAS – like NAP based health check, SSTP based SSL tunnel, IPv6 support in Vista SP1/WS08 and IKEv2 based IPSec tunnel in Windows 7/WS08 R2. &lt;/p&gt;  &lt;p&gt;As a result, we have seen a lot of interesting questions from you- about various design and deployment choices that exists, which one to choose what, when etc.&lt;/p&gt;  &lt;p&gt;In the next few posts, I will walk you through some of the questions that comes in when you designing your remote access solution. The answer to these questions will help you to make informed decisions and make correct choices when deploying RAS based remote access solution. &lt;/p&gt;  &lt;p&gt;Once I finish on these posts on the design side, I will go through configuration and day-to-day management of RAS. &lt;/p&gt;  &lt;p&gt;As always, I will love to hear back from you – your comments/thoughts/need for more articles, etc.&lt;/p&gt;  &lt;p&gt;So lets start the journey. Here is my first post on this topic&lt;/p&gt;  &lt;h5&gt;&lt;a title="_Toc224633136" name="_Toc224633136"&gt;&lt;/a&gt;1.1 Overview&lt;/h5&gt;  &lt;p align="left"&gt;VPN based remote access solution is used to provide access to users connecting network resources over public network. For example, all sizes of companies deploy VPN server at their edge. The employees who work@home or on road connect to the VPN server from their PCs/laptops over Internet. This process establishes a VPN tunnel that virtually places their client PCs/laptops inside intranet and they can now access the intranet resources.&lt;/p&gt;  &lt;p&gt;A remote access solution includes multiple devices– the remote access client devices (PCs, laptops, smart mobile), the remote access server or VPN gateway, network policy server (Radius server), authentication directory or database (Active directory), DHCP server and DNS server. &lt;/p&gt;  &lt;p&gt;My coming posts will be broken in different sections that will assist you in choosing between the various options that may exist in your deployment scenarios and answer some of the important design questions that you may have while choosing those options:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Which VPN client software to use on the remote access devices? &lt;/li&gt;    &lt;li&gt;Which VPN tunnel and authentication protocol to use? &lt;/li&gt;    &lt;li&gt;How to enforce different authorization policies? &lt;/li&gt;    &lt;li&gt;How to enforce health check of the remote access user devices before providing access to the network? How to restrict the unhealthy clients to a quarantine zone? &lt;/li&gt;    &lt;li&gt;What should be the IP subnet that should be allocated to VPN clients? How will the IP routing happen between VPN clients and rest of the network? How will the VPN clients access Internet? &lt;/li&gt;    &lt;li&gt;Where to place the firewall on the VPN server side. Which TCP/UDP ports must be opened to allow VPN tunnels to come in? &lt;/li&gt;    &lt;li&gt;How to provide a high availability solution to the remote access server? &lt;/li&gt; &lt;/ul&gt;  &lt;h5&gt;1.2 Definition&lt;/h5&gt;  &lt;p&gt;Few definitions which I will be referring in my coming posts:&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;&lt;b&gt;Term&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;&lt;b&gt;Description&lt;/b&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;DHCP Relay Agent&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;A VPN server acts as an IP router – forwarding IP packets between VPN clients and rest of intranet machines. To forward DHCP inform requests (for parameters like DNS server address) originated by VPN clients towards the DHCP server on intranet side, DHCP relay agent need to be enabled on VPN server. DHCP relay agent and VPN client supports both the IPv4 and IPv6 transport.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;Intranet&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;Machines sitting on private network side – behind VPN server – that are accessed by VPN client over the VPN tunnel – like file servers, web servers, business application servers etc.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;Internet&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;Machines facing public internet – like the VPN servers.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;Remote Access&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;Technology that enables remote access users to access their remote network – using different technologies like dial-up, VPN etc&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;Remote access user&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;User that accesses the remote network using VPN client&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;RRAS&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;Routing and Remote Access Service – a server role that is part of Network Policy and Access server role inside Windows based server.&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;VPN&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;Virtual Private Network – technology that enables remote access users to access their remote network (like office network) over a public network (like Internet)&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;VPN client&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;Client software that enables remote access user to connect to their remote network – initiator or originating endpoint of VPN tunnel&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="163"&gt;         &lt;p&gt;VPN server&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="635"&gt;         &lt;p&gt;Server software (e.g. RRAS server) that enables remote access user to connect to their remote network – terminating endpoint of the VPN tunnel. &lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;h5&gt;1.3 Further Readings&lt;/h5&gt;  &lt;p&gt;Here are the references to other relevant posts&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-2-vpn-client-software-selection.aspx"&gt;Remote Access Design Guidelines – Part 2: VPN client software selection&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-3-tunnel-selection-authentication-authorization-and-accounting.aspx"&gt;Remote Access Design Guidelines – Part 3: Tunnel selection, Authentication, Authorization and Accounting&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-4-ip-routing-and-dns.aspx"&gt;Remote Access Design Guidelines – Part 4: IP Routing and DNS&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/03/17/remote-access-design-guidelines-part-5-where-to-place-rras-server.aspx"&gt;Remote Access Design Guidelines – Part 5: Where to place RRAS server&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;With Regards,&lt;/p&gt;  &lt;p&gt;Samir Jain&lt;/p&gt;  &lt;p&gt;Senior Program Manager&lt;/p&gt;  &lt;p&gt;Windows Networking&lt;/p&gt;  &lt;p&gt;[This posting is provided “AS IS” with no warranties, and confers no rights.]&lt;/p&gt; &lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3213907" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Change in username format to UTF8 to handle International Characters</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/03/13/change-in-username-format-to-utf8-to-handle-international-characters.aspx</link><pubDate>Fri, 13 Mar 2009 16:06:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3212458</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3212458</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/03/13/change-in-username-format-to-utf8-to-handle-international-characters.aspx#comments</comments><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;As the usage of non-English languages&amp;nbsp;in usernames becomes more and more popular it is important to use the right kind of format for the characters so that the entire&amp;nbsp;character set in these international languages is correctly represented.&amp;nbsp;In Vista/LH&amp;nbsp;ANSI format was used for usernames. ANSI can only represent characters in the 0-127 character set correctly. Extended characters (128-255) are not&amp;nbsp;represented correctly&amp;nbsp;by ANSI. To support complete internationalization the NPS (Microsoft RADIUS server) in Win2K8 R2, by default,&amp;nbsp;expects the characters in the username to be in the UTF-8 format for all authentication protocols.&amp;nbsp;As a result of this change RAS connections from&amp;nbsp;W7 and older RAS clients could fail in certain scenarios, if a Win2K8 R2 NPS is used for authentication. Following are the details of the scenarios that will fail and the workaround to solve the problem&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN-LEFT: 36pt; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;The client is running a version of Windows older than Windows 7 and is using Extensible Authentication Protocol (EAP). Windows 7 clients are not affected because by default RAS client in Windows 7 uses UTF-8 format for EAP-based authentication protocols&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN-LEFT: 36pt; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;The client is running any version of Windows and is using a non-EAP authentication protocol. This is because&amp;nbsp;the RAS client on Windows 7 and earlier versions of Windows uses only ANSI format&amp;nbsp;for non-EAP authentication protocols&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;The above problems can be solved by configuring the NPS to accept ANSI format instead of UTF-8. This can be done by setting a registry key. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 30.75pt; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;a)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Click &lt;B&gt;Start&lt;/B&gt;, click &lt;B&gt;Run&lt;/B&gt;, type &lt;B&gt;regedit&lt;/B&gt;, and then click &lt;B&gt;OK&lt;/B&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 30.75pt; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;b)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;Locate the following registry key:&lt;BR&gt;&lt;B&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost\Configuration&lt;/B&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 30.75pt; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;c)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Click &lt;B&gt;Edit&lt;/B&gt;, click &lt;B&gt;New&lt;/B&gt;, and then click &lt;B&gt;DWord Value&lt;/B&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 30.75pt; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;d)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Type &lt;B&gt;IdentityEncodingFormat&lt;/B&gt;, and then press ENTER.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 30.75pt; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;e)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;Click &lt;B&gt;Edit&lt;/B&gt;, click &lt;B&gt;Modify&lt;/B&gt;, type the value &lt;B&gt;0x1&lt;/B&gt;, and then click &lt;B&gt;OK&lt;/B&gt;.&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 30.75pt; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;f)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-ansi-language: EN-US" lang=EN-US&gt;Exit the Registry Editor.&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The above configuration change would however result in EAP-based authentication from a Windows&amp;nbsp;7 client to fail. To fix this case, the same registry key (shown above) can be set on the Windows&amp;nbsp;7 client so that the Windows 7 client uses ANSI format for EAP-based authentication protocols too. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;FONT size=3 face=Calibri&gt;If you have a mix of remote access clients, you can use this registry setting to configure all servers and clients to use ANSI until you can upgrade all of the clients to a version of Windows that supports UTF-8 for the authentication methods you need to use.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-theme-font: minor-latin; mso-bidi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aanand Ramachandran&lt;/P&gt;
&lt;P&gt;Program Manager, RRAS&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3212458" width="1" height="1"&gt;</description></item><item><title>VPN tunnel strategy - defining the connection order between various tunnel types</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/02/11/vpn-tunnel-strategy-defining-the-connection-order-between-various-tunnel-types.aspx</link><pubDate>Wed, 11 Feb 2009 11:54:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3200722</guid><dc:creator>rrasblog</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3200722</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/02/11/vpn-tunnel-strategy-defining-the-connection-order-between-various-tunnel-types.aspx#comments</comments><description>&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Hello Customers,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;As I wrote in &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx"&gt;&lt;FONT face=Calibri&gt;this&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; blog, there are four types of VPN tunnel supported by Windows 7 based VPN clients. In this blog I will focus on following things: how do you configure tunnel types on the client, how to decide on the tunnel type order while establishing connection, ...&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Lets understand why multiple tunnel types are required. The following factors impact which tunnel gets used for the VPN connection:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;What is the tunnel type &lt;B style="mso-bidi-font-weight: normal"&gt;supported&lt;/B&gt; (at the OS level) and &lt;B style="mso-bidi-font-weight: normal"&gt;configured&lt;/B&gt; at both ends i.e. VPN client and VPN server?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Is there any intermediate agents (like firewalls, NAT, proxies) between both ends - which can &lt;B style="mso-bidi-font-weight: normal"&gt;block&lt;/B&gt; a given tunnel type?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;What is the tunnel &lt;B style="mso-bidi-font-weight: normal"&gt;strategy&lt;/B&gt; (&lt;I style="mso-bidi-font-style: normal"&gt;which I will discuss in this document) &lt;/I&gt;configured on the client side&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Our recommended tunnel types for Windows 7 and above OS clients are IKEv2 followed by SSTP. And as an admin, you must be wondering – how do you migrate your existing PPTP or L2TP/IPSec users to IKEv2 followed by SSTP based deployment because you must be having clients with different OS versions thereby supporting specific tunnel types, you may have different VPN servers which needs to be migrated, etc. This is precisely the scenario where you can use the &lt;B style="mso-bidi-font-weight: normal"&gt;VPN tunnel strategy&lt;/B&gt; feature on the client side which helps you to specify the order in which VPN tunnels are tried – till a given tunnel is able to successfully connect to the VPN server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;There are two types of VPN client supported inside Windows OS:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;In-built Microsoft VPN client that is created using “Setup a connection or network” in “Network and Sharing Center”. This is also called as GCW client (get connected wizard). This is normally done by end-users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Connection Manager (CM) client created using Connection Manager Administration Kit &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;(CMAK). This is normally created by administrators and then shared to end users via email or upload to a file server or a web server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Note: There may be VPN clients built by 3&lt;SUP&gt;rd&lt;/SUP&gt; party vendors. These 3&lt;SUP&gt;rd&lt;/SUP&gt; party VPN clients can be of two types – first one which calls Microsoft VPN client stack using RAS APIs and second one who install their entire VPN client stack on Windows OS. For sake of simplicity, I am not discussing the behaviour of VPN tunnel strategy by 3&lt;SUP&gt;rd&lt;/SUP&gt; party clients.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Now let us see how the tunnel strategy feature works for both types of clients:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Using in-built VPN client, you can configure following types of tunnel strategy - going inside Connection Properties -&amp;gt; Security tab -&amp;gt; Type of VPN&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Automatic: Try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;PPTP: Try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;L2TP/IPSec: Try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;SSTP: Try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;IKEv2: Try &lt;B style="mso-bidi-font-weight: normal"&gt;VPN Reconnect&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;While creating the CM client, the admin can configure following types of tunnel strategy using CMAK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;IKEv2 first:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;IKEv2 only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;VPN Reconnect&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;SSTP first: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;SSTP only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;PPTP first: Try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;PPTP only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;L2TP first: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;L2TP only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Please note:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;For a given VPN tunnel type, let us say the tunnel establishment phase succeeds but the entire VPN connection fails - due to authentication issue OR IP address negotiation issue. This doesn’t mean VPN client will try the next tunnel type based upon the tunnel strategy. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;The VPN client tries different tunnel types only if the tunnel establishment fails. This can happen because VPN server is not configured/supports given tunnel type OR packets for a given tunnel type are getting dropped.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;The time it takes to try next tunnel – varies between each tunnel – based upon the retries. For example, IKEv2 tunnel sends 3 retries for first IKEv2 packet spaced at 1, 2 and 4 seconds – hence it will take atleast 7 seconds before next tunnel type is tried. SSTP tunnel takes 10-20 seconds (depending upon the connection is going through a proxy enabled for WPAD or not) to detect failure. And so on.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;If a given tunnel is reachable via IPv4 as well as IPv6 and VPN client is configured with “hostname” of VPN server, then both IPv4 and IPV6 addresses are tried before trying the next tunnel type as given in VPN strategy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;For in-built VPN clients, the last successful VPN tunnel type is tried next time for “Automatic” tunnel type and if that fails it follows the order (as given above) again. However for CM based VPN clients, every VPN connection tries the same order. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Now let us take some deployment scenario:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Assume you have WS2003 VPN servers configured for PPTP and have different VPN users (XP, Vista, Windows 7). And you plan to move users to IKEv2 and SSTP tunnel scenario. You can follow this deployment plan:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level2 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Upgrade all your VPN servers to Windows 7 Server and configure PPTP, SSTP and IKEv2 on the server side.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level2 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Create different CM package for XP and Windows 7.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In the XP package give PPTP only as the VPN Strategy and in W7 package give&amp;nbsp;IKEv2 first as the VPN strategy. Note: W7 package if installed on Vista machine automatically switches to SSTP first (as IKEv2 is not available on Vista).&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level2 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Send the XP&amp;nbsp; package&amp;nbsp;to XP users and W7 package to Vista + W7 users. And you are all set.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Now as part of deployment plan – you may want to upgrade your VPN servers one-at-a-time. In that case at some point you may be having WS2003 (enabled for PPTP) and Windows 7 server (enabled for PPTP, SSTP, IKEv2) running at the same time. This may mean any client (XP, Vista, Windows 7) may connect to either of the VPN Servers. It should not be a connectivity establishment problem with the above CM package – however Windows 7 users may face “longer connection establishment time” (like 30 seconds) if they connect to Windows 2003 VPN servers &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;as it tries IKEv2 followed by SSTP followed by PPTP.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 18pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;To summarize, the VPN tunnel strategy helps your VPN client to try different tunnel types in a given order and thereby helping you to migrate your remote access users to newer secured tunnel types. Hope this blog helps you in that direction.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;For further references:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx"&gt;&lt;FONT face=Calibri&gt;Different VPN tunnel types in Windows&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2007/06/07/timings-for-transition-from-one-tunnel-type-to-another.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2007/06/07/timings-for-transition-from-one-tunnel-type-to-another.aspx"&gt;&lt;FONT face=Calibri&gt;How automatic tunnel types work in Vista&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2006/11/01/vista-lh-frequently-asked-questions-on-ipv6-support-for-remote-access-scenarios-ras.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2006/11/01/vista-lh-frequently-asked-questions-on-ipv6-support-for-remote-access-scenarios-ras.aspx"&gt;&lt;FONT face=Calibri&gt;Frequently asked Questions on IPv6 support of RAS&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;With Regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Samir Jain&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Windows Networking&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri" lang=EN&gt;&lt;FONT face=Calibri&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3200722" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/SSTP/">SSTP</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/PPTP/">PPTP</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/IKEv2/">IKEv2</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/L2TP/">L2TP</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>How to change certificate on SSTP server - in Windows server 2008 R2</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/02/11/sstp-certificate-selection.aspx</link><pubDate>Wed, 11 Feb 2009 09:38:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3200670</guid><dc:creator>rrasblog</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3200670</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/02/11/sstp-certificate-selection.aspx#comments</comments><description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;Very soon Windows 7 and Windows Server 2008 R2 will be released and it is very exciting that beta version of these new operating system is available for public download. So, go ahead and start using it and provide your valuable feedback to us. &lt;/P&gt;
&lt;P&gt;In this blog I will talk about a new feature in RRAS for SSTP tunnel. In WS08, we added SSTP tunnel as a new VPN tunneling mechanism which allow enterprises to have the VPN available even though the user [remote access client] is behind the firewall or NAT device. This eases lot of deployment and support calls wherein the users were not able to connect to the enterprise due to firewall\NAT related issues. &lt;/P&gt;
&lt;P&gt;Currently, SSTP by default picks up a certificate available in the cert store and do the SSL bi&lt;B&gt;n&lt;/B&gt;ding of the same and cache that information to do the crypto biding for inbound connection. This certificate selection by SSTP is not very intuitive for administrators, as administrator does not know which certificate is currently used by SSTP as there is no display available, also it does not provide a mechanism to the RRAS administrator to select specific certificate for the SSL binding by the SSTP. In case of mismatch between SSL binding and Crypto hash, SSTP will not function properly. &lt;/P&gt;
&lt;P&gt;To enhance the deployment ease, we have provided UI and net shell interface to handle the certificate selection to the user, here is the new scenario\behavior.&lt;/P&gt;
&lt;P&gt;To be able to see the certificate selection UI, please do the following steps: Open the rrasmgmt.msc, select the targeted server and right click. Click on the properties option, this will open a tab based dialog box, select the Security Tab. In the Security tab, you will see the SSL certificate binding option at the bottom of the page as illustrated in &lt;B&gt;&lt;I&gt;pic 1&lt;/I&gt;&lt;/B&gt;. Administrator selects one of the provisioned certificates for SSL binding here on this page, Refer to the UI below. RRAS UI picks up and displays the valid certificates in the Certificate drop-down menu from Local M\c personal cert store. User can check currently provisioned certificate using certificate snap-in the WS08 R2. Once user selects\configures a certificate, UI will prompt for restarting the Remote access service (including SSTP service). SSL (SSTP service) binds to selected certificate once remote service is restarted. If remote access service is not running then binding will take place whenever remote access (SSTP service in particular) comes up. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image002_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image002_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=clip_image002 border=0 alt=clip_image002 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image002_thumb.jpg" width=174 height=244 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image002_thumb.jpg"&gt;&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Pic. 1 &lt;/B&gt;Certificate Selection UI&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Note 1&lt;/B&gt;: In case of default certificate selection in the drop down menu, SSTP service will pick a certificate from the local computer personal store and do the binding. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;Note 2&lt;/B&gt;: In case if the currently SSL is bound to some certificate and that binding is done by some other application, UI will throw an error as illustrated in &lt;B&gt;&lt;I&gt;Pic 2&lt;/I&gt;&lt;/B&gt;. Administrator needs to correct this anomaly manually. Please see the netsh commands to see\delete\add the SSL binding in the netsh section below. There are 3 ways to fix it. &lt;/P&gt;
&lt;P&gt;a) Let the other application also use the same certificate as used by SSTP &lt;/P&gt;
&lt;P&gt;b) Choose the same certificate as used by the other application. &lt;/P&gt;
&lt;P&gt;c) Choose default option in the drop down menu.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image004_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image004_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=clip_image004 border=0 alt=clip_image004 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image004_thumb.jpg" width=244 height=106 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image004_thumb.jpg"&gt;&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Pic 2: &lt;/B&gt;Error Dialog in case of certificate mismatch&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Note 3&lt;/B&gt;: In case when the selected certificate is deleted after the SSTP is configured by admin, when admin open the security tab, an error will be thrown stating that the certificate is missing as shown in &lt;B&gt;&lt;I&gt;Pic 3&lt;/I&gt;&lt;/B&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image006_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image006_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=clip_image006 border=0 alt=clip_image006 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image006_thumb.jpg" width=244 height=85 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/SSTPCertificateselection_AAAF/clip_image006_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Pic 3: &lt;/B&gt;Error Dialog in case of certificate is deleted after configuring SSTP&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;With this UI, we also support configuration for SSTP in reverse proxy scenario. This can be done by having the check box “Use Http” checked. This configures SSTP to receive the plain HTTP packet as SSL is offloaded to proxy. In this case, user needs to manually configure the Certificate Hash in the registry manually, as done in Windows Server 2008 &lt;/P&gt;
&lt;P&gt;RAS administrator can also use net shell command to do the same thing (selecting the certificate). Behavior is same as described above.&lt;/P&gt;
&lt;P&gt;· Each time remote access service is started SSL will bind to certificate configured (in RAS) if any. If certificate configured is not present in cert store then RRAS will cleanup the SSL cert binding. An &lt;I&gt;ERROR&lt;/I&gt; event (Shown below) will also be logged in this case.&lt;/P&gt;
&lt;P&gt;· SSTP service would continue to bind the certificate for both IPV4 &amp;amp; IPV6. This behaviour is same as LH. It is irrespective of whether administrator has selected the certificate or the certificate is chosen based on existing logic (SSTP logic of selecting certificate from store) or choosing the same certificate as current SSL binding (If SSL is already bound by some other web server applications).&lt;/P&gt;
&lt;P&gt;While Configuring the certificate for SSL binding if the SSL binding already exist with some other cert by some application, UI\Netsh will inform the user about the mismatch so that user can select some other cert or remove the incorrect existing binding using the netsh command &lt;/P&gt;
&lt;P&gt;&lt;B&gt;Netsh Command to configure the cert for SSTP&lt;/B&gt;:&lt;/P&gt;
&lt;P&gt;Netsh ras set sstp-ssl-cert name=&amp;lt;Cert Name&amp;gt;&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;Netsh ras set sstp-ssl-cert hash=&amp;lt;Cert SHA-1 hash&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Netsh Command to see the current configured cert for SSTP&lt;/B&gt;:&lt;/P&gt;
&lt;P&gt;netsh ras show sstp-ssl-cert&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Netsh command to see and delete the current SSL binding&lt;/B&gt;:&lt;/P&gt;
&lt;P&gt;netsh http show sslcert&lt;/P&gt;
&lt;P&gt;netsh http delete sslcert ipport=&amp;lt;v4\v6 Address&amp;gt;:443&lt;/P&gt;
&lt;P&gt;With Regards,&lt;/P&gt;
&lt;P&gt;Dhiraj Gupta&lt;/P&gt;
&lt;P&gt;Software Design Engineer&lt;/P&gt;
&lt;P&gt;Windows Networking Group&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3200670" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/SSTP/">SSTP</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category></item><item><title>Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx</link><pubDate>Tue, 10 Feb 2009 14:40:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3200123</guid><dc:creator>rrasblog</dc:creator><slash:comments>12</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3200123</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Hi Folks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Our team member Samir Jain has posted a nice blog on how you should decide which tunnel to use/deploy for your scenario. The details for the same are given at&amp;nbsp;&lt;A title="Which tunnel to use" href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx"&gt;which tunnel to use&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In this blog, I&amp;nbsp;would like&amp;nbsp;to understand&amp;nbsp;further on a possibility of&amp;nbsp;deprecating PPTP &amp;amp; L2TP/IPsec VPN tunnels&amp;nbsp;going forward - i.e. after Windows 7. This leaves&amp;nbsp;in-the-box Microsoft VPN component&amp;nbsp;supporting SSTP (SSL based )&amp;nbsp;and IKEv2 (IPsec based) VPN tunnel. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Please &lt;STRONG&gt;do not panic&lt;/STRONG&gt;&amp;nbsp;! This has not happened yet.&amp;nbsp;I am just trying to get your feedback and learn more about your deployment plans going forward.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Why do I think you should migrate to IKEv2/SSTP?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;IKEv2 (VPN Reconnect) is a standard based tunnel&amp;nbsp;that should work with any third party servers so interoperability should not be any less if compare to PPTP or L2TP. SSTP allows SSL based firewall traversal thereby supporting ubiquitous VPN connectivity.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Both tunnels are on par or better&amp;nbsp;with L2TP/IPsec&amp;nbsp;as well&amp;nbsp;as PPTP - in terms of security, performance, connection establishment experience etc. &lt;/FONT&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" class=MsoTableGrid border=1 cellSpacing=0 cellPadding=0 class="MsoTableGrid"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: black 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 0.95in; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1" vAlign=top width=91&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;IKEv2&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" vAlign=top width=396&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Does not require client side PKI deployment or pre-shared key.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Integrates well with all EAP based methods&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Leverages the security strength provided by IPsec&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Better in connectivity time compare to L2TP/IPsec&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;5.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Provide mobility switchover support (&lt;A title="mobility manager" href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx"&gt;mobility manager&lt;/A&gt;)&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 113.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" vAlign=top width=151&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Windows 7 &amp;amp; WS08 R2 onwards&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: black 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 0.95in; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-themecolor: text1; mso-border-top-alt: solid black .5pt" vAlign=top width=91&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;SSTP&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" vAlign=top width=396&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Does not require client side PKI deployment or pre-shared key.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Integrates well with all EAP based methods&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Leverages the security strength provided by SSL protocol&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Provides firewall traversal&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 113.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" vAlign=top width=151&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Vista SP1 &amp;amp; WS08 onwards&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Why we would like to deprecate PPTP/L2TP?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Enables better usability (less #&amp;nbsp;of tunnel choices confusing admins) &amp;amp; better troubleshooting/diagnostics support&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Reduces the support: Reduces the&amp;nbsp;footprint and the number&amp;nbsp;of updates.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Better focus from Microsoft:&amp;nbsp;Our development&amp;nbsp;team can focus mainly on these two tunnels and focus on improving &amp;nbsp;the remote access connectivity experience.&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;I do understand that PPTP is a highly deployed VPN tunnel followed by L2TP/IPSec and Windows 7 will take&amp;nbsp;sometime before&amp;nbsp;it is wide-spread inside organizations (like XP is&amp;nbsp;today).&amp;nbsp;&amp;nbsp;However, we do feel announcing now and deprecating&amp;nbsp;PPTP/L2TP &lt;/FONT&gt;after Windows 7&amp;nbsp; would have provided ample time to our customers to migrate to SSTP (Vista SP1 &amp;amp; WS08 onwards) and IKEv2 (available Windows 7 &amp;amp; WS08 R2 onwards).&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;Again - to re-iterate, there is &lt;STRONG&gt;no official plan in this direction&lt;/STRONG&gt; and this blog post is purely a &lt;STRONG&gt;feedback&amp;nbsp;gaining&amp;nbsp;mechanism&amp;nbsp;&lt;/STRONG&gt;to hear from our enthusiastic&amp;nbsp;remote access&amp;nbsp;customers about&amp;nbsp;their deployment and migration plans to our newer OS supporting exciting new VPN tunnels.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Please share your feedback - either as comment or by&amp;nbsp;sending us an&amp;nbsp;email.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Looking forward to hear back from you&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Cheers,&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Abhishek Tiwari&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Senior Lead Program Manager, &lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;RAS Team, &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Windows Networking&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN" lang=EN&gt;&lt;FONT face=Calibri&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3200123" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/SSTP/">SSTP</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/PPTP/">PPTP</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/IKEv2/">IKEv2</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/L2TP/">L2TP</category></item><item><title>RRAS Performance results</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/02/09/rras-performance-results.aspx</link><pubDate>Mon, 09 Feb 2009 14:06:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3199187</guid><dc:creator>rrasblog</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3199187</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/02/09/rras-performance-results.aspx#comments</comments><description>&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Hello Customers,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;A lot of you have requested directly or through the field channels about performance results of RRAS &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;for different VPN tunnel types – specifically SSTP. I am writing this blog to share the results for the tests done internally by our test team (thanks Sai and other test team members). &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;First, a few &lt;B style="mso-bidi-font-weight: normal"&gt;guidelines&lt;/B&gt; to help you better interpret the test and results:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;The main goal of this performance test is to validate a target VPN server deployment in terms of the performance requirements i.e. x number of simultaneous VPN connections doing y Mbps of aggregated data transfer on a specific hardware.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;The number of simultaneous VPN connections and aggregated VPN server throughput that we have used in the test are some of our internal benchmark numbers – based upon our understanding of common customer deployment scenarios of RRAS. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;This by no means is the only deployment scenario of RRAS. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;The performance numbers without hardware specification is meaningless. Hence, we have shared the details of server hardware used in our performance lab. However, this should not be read as Microsoft recommended hardware platform for RRAS. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;All our tests are done inside our lab environment which means minimal delay (&amp;lt; 10msec) and close to zero % data loss. You may say that is not close to real deployment. And the way I see this – the delay and loss may change the data throughput numbers as experienced by a VPN client for a given tunnel type. However delay and loss doesn’t drastically change the aggregated throughput as seen on VPN server and our focus has been on VPN server performance – hence this set-up. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;This blog is focussed on Windows server 2008 as the VPN server and performance is compared between PPTP and SSTP. I will extend this blog with Windows 7 results shortly – including results for “VPN reconnect” or IKEv2 based VPN tunnel.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Setup:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;1 VPN server:&lt;B style="mso-bidi-font-weight: normal"&gt; &lt;/B&gt;HP DL 165 G5 server with two AMD Opteron™ 2352 Quad Core Processor 2.10 GHz, 16GB RAM, two 1 Gig Ethernet port – running Windows server 2008 released version.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;10 machines - code changed to emulate &lt;I style="mso-bidi-font-style: normal"&gt;n&lt;/I&gt; VPN client connections per machine. Each of these machines are running internal tools to manage VPN connection management and generated data load.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;All machines connected on a Gigabit Ethernet switched network. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Performance Test 1:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Generate 100 Mbps data load using &lt;B style="mso-bidi-font-weight: normal"&gt;1000&lt;/B&gt; &lt;B style="mso-bidi-font-weight: normal"&gt;VPN clients&lt;/B&gt;. Measure the average CPU utilization on the VPN Server.&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid #4BACC6 1.0pt; mso-border-themecolor: accent5; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" class=MsoTableLightGridAccent5 border=1 cellSpacing=0 cellPadding=0 class="MsoTableLightGridAccent5"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: -1; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-bottom-themecolor: accent5" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 5" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Tunnel Type&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Average CPU usage (sum of CPU usage per core/no of core) – in %&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Data Throughput (on VPN server) – in Mega bits/sec&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 0"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;PPTP &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;13.23&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;100&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;SSTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;33.65&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;100&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Performance Test 2: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Generate maximum data load from a &lt;B style="mso-bidi-font-weight: normal"&gt;single VPN client&lt;/B&gt; connection. Measure the aggregate data throughput and average CPU utilization on the VPN server&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid #4BACC6 1.0pt; mso-border-themecolor: accent5; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" class=MsoTableLightGridAccent5 border=1 cellSpacing=0 cellPadding=0 class="MsoTableLightGridAccent5"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: -1; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-bottom-themecolor: accent5" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 5" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Tunnel Type&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Average CPU usage (sum of CPU usage per core/no of core) – in %&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Maximum Data Throughput (on VPN server) – in Mega bits/sec&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 0"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;PPTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;40.29&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;644.78&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;SSTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;71.44&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;685.96&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Performance Test 3:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Generate a constant background data load (0, 25 Mbps, 100 Mbps) using &lt;B style="mso-bidi-font-weight: normal"&gt;1000&lt;/B&gt; &lt;B style="mso-bidi-font-weight: normal"&gt;VPN clients&lt;/B&gt; and in parallel start a 580 Mega byte file transfer from one of the VPN client to machine behind VPN Server. Measure the file transfer time and average CPU utilization on the VPN Server.&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid #4BACC6 1.0pt; mso-border-themecolor: accent5; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" class=MsoTableLightGridAccent5 border=1 cellSpacing=0 cellPadding=0 class="MsoTableLightGridAccent5"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: -1; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-bottom-themecolor: accent5" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 5" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Tunnel Type&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Average CPU usage (sum of CPU usage per core/no of core) – in %&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4bacc6 1pt solid; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;Time taken to transfer 580 MB file&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- in seconds&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 0"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;PPTP with 0 Mbps of traffic&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;26.42&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;14&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;PPTP with 25 Mbps of traffic&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;27.24&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;20&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;PPTP with 100 Mbps of traffic&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;33.08&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;30&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;SSTP with 0 Mbps of traffic&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;30.38&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;13&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 4"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;SSTP with 25 Mbps of traffic&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;40.91&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d2eaf1; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt; mso-background-themecolor: accent5; mso-background-themetint: 63" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;18&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 5; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #4bacc6 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 159.6pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=266&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin; mso-bidi-theme-font: major-bidi"&gt;&lt;FONT size=3&gt;SSTP with 100 Mbps of traffic&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 187.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=312&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;61.22&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4bacc6 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 163pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4bacc6 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent5; mso-border-top-themecolor: accent5; mso-border-right-themecolor: accent5; mso-border-left-alt: solid #4BACC6 1.0pt; mso-border-left-themecolor: accent5; mso-border-top-alt: solid #4BACC6 1.0pt" vAlign=top width=272&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;18&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;I hope that the above performance results helps you better understand and evaluate RRAS performance and do capacity planning for your deployment. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The performance measurement is a difficult field with various factors affecting numbers. My recommendation is to evaluate the performance in view of your WAN bandwidth of VPN server and number of clients connecting to it – as these parameters are closest and most important to a practical deployment. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;I will like to hear back from you, so feel free to send in your comments on this blog or send us email to our blog link as mentioned above. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;With Regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Samir Jain&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Windows Networking&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN" lang=EN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3199187" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Load+Balancing/">Load Balancing</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/Design/">Design</category></item><item><title>Deploying VPN Reconnect: Step-by-step guide available at </title><link>http://blogs.technet.com/b/rrasblog/archive/2009/02/01/vpn-reconnect-deployment-guide.aspx</link><pubDate>Sun, 01 Feb 2009 19:46:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3195520</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/rrasblog/rsscomments.aspx?WeblogPostID=3195520</wfw:commentRss><comments>http://blogs.technet.com/b/rrasblog/archive/2009/02/01/vpn-reconnect-deployment-guide.aspx#comments</comments><description>&lt;P&gt;Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; The deployment guide for VPN Reconnect is now available at&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;A href="http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc" mce_href="http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc"&gt;&lt;FONT size=3 face="Times New Roman"&gt;http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The guide covers the various requirements for deploying VPN Reconnect and detail steps to configure the various Network Elements. If you have any questions please feel free to post them on this blog or email rrasblog&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&amp;nbsp;&amp;nbsp; Aanand&lt;/SPAN&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3195520" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/IKEv2/">IKEv2</category><category domain="http://blogs.technet.com/b/rrasblog/archive/tags/How_2D00_To/">How-To</category></item></channel></rss>
