<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Do we still need PPTP &amp;amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx</link><description>Hi Folks, Our team member Samir Jain has posted a nice blog on how you should decide which tunnel to use/deploy for your scenario. The details for the same are given at which tunnel to use . In this blog, I would like to understand further on a possibility</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3201099</link><pubDate>Thu, 12 Feb 2009 08:28:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3201099</guid><dc:creator>Joseph Worrall</dc:creator><description>&lt;p&gt;There are a number of cases where our customers use PPTP for site to site RRAS VPN links because of the complexity of setting up L2TP.&lt;/p&gt;
&lt;p&gt;1. Is SSTP supported in Windows 2008 for site to site links? 2. Is SSTP and IKEv2 supported in Windows 2008 R2 for site to site links?&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3201109</link><pubDate>Thu, 12 Feb 2009 09:26:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3201109</guid><dc:creator>SamirJ [MSFT]</dc:creator><description>&lt;p&gt;Joseph Worall wrote:&lt;/p&gt;
&lt;p&gt;Is SSTP supported in Windows 2008 for site to site links? 2. Is SSTP and IKEv2 supported in Windows 2008 R2 for site to site links?&lt;/p&gt;
&lt;p&gt;SAMIRJ [MSFT] response:&lt;/p&gt;
&lt;p&gt;You are very correct. SSTP-IKEv2 are not supported for site-to-site scenario. However that support can be added. We do feel IKEv2 for site-to-site scenario makes more sense compared to SSTP (because site-to-site scenario is more a fixed or static scenario and you don't need to worry about firewall traversal - hence SSTP is not required in this scenario). If we add IKEv2 for RAS site-to-site scenario, will that suffice ...&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3201328</link><pubDate>Thu, 12 Feb 2009 19:09:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3201328</guid><dc:creator>ck</dc:creator><description>&lt;p&gt;I think until you back port SSTP at least to XP it's going to be hard to deprecate PPTP. Many companies will not be Vista/win7 only for many years to come.&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3201561</link><pubDate>Fri, 13 Feb 2009 02:42:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3201561</guid><dc:creator>Jesper Ravn</dc:creator><description>&lt;p&gt;Hi Abhishek and Samir&lt;/p&gt;
&lt;p&gt;I very much agree with CK. The SSTP client should have been back ported to XP.&lt;/p&gt;
&lt;p&gt;Many customers were ready for SSTP with NAP. But the lack of support in XP, and an aversion to Vista, meant they selected 3-party products eg Citrix or Cisco&lt;/p&gt;
&lt;p&gt;With Direct Access, history repeats itself. Microsoft now requires that you must have SA to use this feature. Alternatively, you can use the UAG, which is still in beta.&lt;/p&gt;
&lt;p&gt;Please change this SA feature strategi in generel and give us something to work with.&lt;/p&gt;
&lt;p&gt;/Jesper&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3201655</link><pubDate>Fri, 13 Feb 2009 08:00:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3201655</guid><dc:creator>rrasblog</dc:creator><description>&lt;p&gt;Jesper Wrote:&lt;/p&gt;
&lt;p&gt;====&lt;/p&gt;
&lt;p&gt;I very much agree with CK. The SSTP client should have been back ported to XP.&lt;/p&gt;
&lt;p&gt;Many customers were ready for SSTP with NAP. But the lack of support in XP, and an aversion to Vista, meant they selected 3-party products eg Citrix or Cisco&lt;/p&gt;
&lt;p&gt;====&lt;/p&gt;
&lt;p&gt;Hi Jesper/Joseph/CK,&lt;/p&gt;
&lt;p&gt;I agree with you that backporting SSTP in XP would have increased the penetration for SSTP but for business reasons this plan was not approved. On the other hand, I wonder if deployment for XP would be still significant for post W7 release time (PPTP/L2TP are supported in W7) which is definitly few years away. &lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Abhishek&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3201722</link><pubDate>Fri, 13 Feb 2009 12:01:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3201722</guid><dc:creator>Patrick</dc:creator><description>&lt;p&gt;We have a lot of customers who are still migrateing from 2K to XP. Vista will never be used by them. If they take the step to 7 in maybe 3-4 years is not known.&lt;/p&gt;
&lt;p&gt;Also none of our customers use a MS Server as VPN Gateway. there are some &amp;gt;20K Remote User customers and they would like to use the MS IPSec/L2TP Client controlled by our Client using RAS Api in the future.&lt;/p&gt;
&lt;p&gt;As long as SSTP is not compatible with Cisco or Checkpoint Gateways it will not widely be used.&lt;/p&gt;
&lt;p&gt;And a backport of SSTP and IKEv2 (compatible with other vendr gateways) to Vista &amp;amp; XP would be the right choice for you. Also on Windows Mobile. Drop that stupid Connection Manager, include RAS Custom DLLs and NAT-T and everony will be happy...&lt;/p&gt;
&lt;p&gt;BTW. i hope you post it as soon as possible if you are going to remove PPTP or IPSec/L2TP because than we have to think about creating our own stack or start looking for SDK Vendors...&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3202244</link><pubDate>Sat, 14 Feb 2009 21:40:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3202244</guid><dc:creator>Simon</dc:creator><description>&lt;p&gt;Unfortunately some devices have not yet (even with more recent releases) added support for either SSTP or IKEv2 and retain only support for PPTP and L2TP; Windows Mobile 6.1 being a perfect example, it came out recently and still doesn't have support for any new protocols.&lt;/p&gt;
&lt;p&gt;You also really do need to retain some site-to-site VPN protocols for backwards compatibility with previous server versions of Windows so unless you can get site-to-site support in Windows 2008 R2 for both IKEv2 and SSTP removing other protocols in the version after 2008 R2 will result in no support for any prior versions, which would be a killer I suspect.&lt;/p&gt;
&lt;p&gt;I think you actually need to retain at least one of them (perhaps L2TP as it can support IPv6 and better security) for a considerable time; at least the next TWO versions of Windows Server.&lt;/p&gt;
&lt;p&gt;Otherwise you will need to either provide an out-of-band installable version of one of the newer protocols or just give up and recommend other manufacturers solutions.&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3203277</link><pubDate>Tue, 17 Feb 2009 07:18:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3203277</guid><dc:creator>SamirJ [MSFT]</dc:creator><description>&lt;p&gt;Thanks Simon and Patrick for your feedback - related to PPTP/L2TP usage in site-to-site scenario, MS client with 3rd party VPN servers and for mobile clients. All are very valid scenarios.&lt;/p&gt;
&lt;p&gt;And just to re-iterate what Abhishek wrote above - please do view this discussion more as your feedback to our product team - instead of product team communicating a deprecation announcement. We sincerely appreciate your feedback. And please continue to use our VPN solution - both on client as well as server side.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Samirj&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3206002</link><pubDate>Tue, 24 Feb 2009 11:43:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3206002</guid><dc:creator>Craig</dc:creator><description>&lt;p&gt;From reviewing this information, it seems that L2TP remains the only protocol makes it possible to authenticate a corporate asset (i.e. computer certificate) as well as the user (i.e. MSCHAP or user certificate).&lt;/p&gt;
&lt;p&gt;Am I reading the summary in the &amp;quot;which tunnel to use&amp;quot; hyperlink correctly?&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3206085</link><pubDate>Tue, 24 Feb 2009 15:14:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3206085</guid><dc:creator>SamirJ [MSFT]</dc:creator><description>&lt;p&gt;Craig wrote:&lt;/p&gt;
&lt;p&gt;From reviewing this information, it seems that L2TP remains the only protocol makes it possible to authenticate a corporate asset (i.e. computer certificate) as well as the user (i.e. MSCHAP or user certificate).&lt;/p&gt;
&lt;p&gt;Am I reading the summary in the &amp;quot;which tunnel to use&amp;quot; hyperlink correctly?&lt;/p&gt;
&lt;p&gt;SAMIRJ Response:&lt;/p&gt;
&lt;p&gt;That is correct.&lt;/p&gt;
&lt;p&gt;PPTP and SSTP does only user authentication at PPP layer.&lt;/p&gt;
&lt;p&gt;L2TP/IPSec does first machine level authentication at IPSec level followed by (AND) user authentication at PPP layer.&lt;/p&gt;
&lt;p&gt;IKEv2 aka VPN reconnect supports machine authentication OR user authentication.&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3207842</link><pubDate>Sun, 01 Mar 2009 10:31:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3207842</guid><dc:creator>anonymuos</dc:creator><description>&lt;p&gt;Yes, please backport SSTP and VPN Reconnect (IKEv2) to XP. Direct Access should also be backported to Server 2008 and Server 2003.&lt;/p&gt;
</description></item><item><title>re: Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx#3208340</link><pubDate>Mon, 02 Mar 2009 20:41:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3208340</guid><dc:creator>fo</dc:creator><description>&lt;p&gt;The ability to authenticate with a user certificate AND a computer certificate is a 'must' for some government agencies.&lt;/p&gt;
</description></item></channel></rss>