<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Routing and Remote Access Blog : IKEv2</title><link>http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx</link><description>Tags: IKEv2</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Enhancements to VPN Reconnect in W7 RC</title><link>http://blogs.technet.com/rrasblog/archive/2009/05/11/enhancements-to-vpn-reconnect-in-w7-rc.aspx</link><pubDate>Mon, 11 May 2009 16:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3238840</guid><dc:creator>rrasblog</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3238840.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3238840</wfw:commentRss><description>&lt;P&gt;Hello Folks,&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;By now all of you must have heard about the formal release of W7 RC. In case you don’t have it already here is the link from where you can download the RC bits&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://www.microsoft.com/windows/windows-7/default.aspx" mce_href="http://www.microsoft.com/windows/windows-7/default.aspx"&gt;&lt;SPAN style="COLOR: windowtext"&gt;&lt;FONT size=3 face=Calibri&gt;http://www.microsoft.com/windows/windows-7/default.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In RC the RAS team has made some enhancements to the VPN Reconnect feature. Here are the details of the change and some recommendations on deployment. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Change in method used to calculate MSK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold; mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Details of Enhancement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In accordance with the IKEv2 RFC, in EAP &amp;nbsp;authentication, the shared secret generated is used by the IKEv2 connection initiator and responder to generate AUTH payloads &amp;nbsp;for EAP (see section 2.16 in RFC 4306 for more details). This shared secret is called the MSK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;FONT size=3 face=Calibri&gt;In W7 RC we have changed the method used to calculate the MSK for EAP-MSCHAPv2 . The new method has been documented on MSDN and can be found at &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx"&gt;&lt;FONT size=3 face=Calibri&gt;http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Impact&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The MSK calculation method used in RC is different from that in Beta and implementation of the new method involved changes on both the client and server. Hence RC build is required on both client and server to successfully setup an IKEv2 connection using EAP-MSCHAPv2 authentication. IKEv2 connections between Beta client and RC server and vice versa will fail if EAP-MSCHAPv2 authentication is used &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Vendors implementing EAP-MACHAPv2 for IKEv2 MUST derive the MSK as specified in &lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx"&gt;http://msdn.microsoft.com/en-us/library/cc224635(PROT.13).aspx&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-weight: bold"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Validation of VPN server machine certificate by client for better security&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Details of Enhancement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;We have made a change to IKEv2 on the client side to start validating the machine certificate sent by the VPN server that it is connecting to. This change helps prevent possible MITM and dictionary attacks thereby strengthening IKEv2 security. It is not possible to disable these checks on the client&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 35.45pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Deployment Recommendation&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 2cm; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Certificate installed on the server should have the following values for certain important fields in the certificate. Corresponding root certificates should be installed on the client&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Certificate Name (CN): This field should contain the name or IP address of the server (depending on which one is being used by the client) that is&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; being validated by the client. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="mso-fareast-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;EKU: Should be a ‘Server Authentication’ certificate. If there are multiple certificates present in the machine store of the server then additionally &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; specifying ‘&lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'MS Shell Dlg 2','sans-serif'; FONT-SIZE: 10pt; mso-ansi-language: EN-US" lang=EN-US&gt;IP security IKE intermediate’ (OID: 1.3.6.1.5.5.8.2.2)&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt; in the EKU of the cert will ensure that the cert is picked over other certificates in the &lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 67.6pt; mso-list: l3 level1 lfo4" class=MsoListParagraph&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; store. The latter is &lt;B&gt;highly recommended&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 2cm; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;If you are running SSTP already in your setup then the same server machine certificate can be used for both SSTP and IKEv2 but the certificate should satisfy the criteria mentioned above. Since root certs required for SSTP are already present on the client no client side changes are needed in this case&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Impact/Troubleshooting Tips&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-IN; mso-bidi-language: AR-SA"&gt;If right certificate is not configured on IKEv2 server or if correct trusted root certificate is not present on the client then IKEv2 connections might fail. Error code seen &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-IN; mso-bidi-language: AR-SA"&gt;is 13801 which indicates that validation of the server certificate is failing. If multi-tunnel VPN strategy is used, then a fall back to the next tunnel will happen and the &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: 36pt; MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-ansi-language: EN-IN; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-IN; mso-bidi-language: AR-SA"&gt;VPN connection will go through. For e.g. for ‘Automatic’ tunnel type fall back will happen to SSTP&lt;/SPAN&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3238840" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category></item><item><title>VPN tunnel strategy - defining the connection order between various tunnel types</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/11/vpn-tunnel-strategy-defining-the-connection-order-between-various-tunnel-types.aspx</link><pubDate>Wed, 11 Feb 2009 11:54:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3200722</guid><dc:creator>rrasblog</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3200722.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3200722</wfw:commentRss><description>&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Hello Customers,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;As I wrote in &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx"&gt;&lt;FONT face=Calibri&gt;this&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; blog, there are four types of VPN tunnel supported by Windows 7 based VPN clients. In this blog I will focus on following things: how do you configure tunnel types on the client, how to decide on the tunnel type order while establishing connection, ...&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Lets understand why multiple tunnel types are required. The following factors impact which tunnel gets used for the VPN connection:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;What is the tunnel type &lt;B style="mso-bidi-font-weight: normal"&gt;supported&lt;/B&gt; (at the OS level) and &lt;B style="mso-bidi-font-weight: normal"&gt;configured&lt;/B&gt; at both ends i.e. VPN client and VPN server?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Is there any intermediate agents (like firewalls, NAT, proxies) between both ends - which can &lt;B style="mso-bidi-font-weight: normal"&gt;block&lt;/B&gt; a given tunnel type?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;What is the tunnel &lt;B style="mso-bidi-font-weight: normal"&gt;strategy&lt;/B&gt; (&lt;I style="mso-bidi-font-style: normal"&gt;which I will discuss in this document) &lt;/I&gt;configured on the client side&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Our recommended tunnel types for Windows 7 and above OS clients are IKEv2 followed by SSTP. And as an admin, you must be wondering – how do you migrate your existing PPTP or L2TP/IPSec users to IKEv2 followed by SSTP based deployment because you must be having clients with different OS versions thereby supporting specific tunnel types, you may have different VPN servers which needs to be migrated, etc. This is precisely the scenario where you can use the &lt;B style="mso-bidi-font-weight: normal"&gt;VPN tunnel strategy&lt;/B&gt; feature on the client side which helps you to specify the order in which VPN tunnels are tried – till a given tunnel is able to successfully connect to the VPN server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;There are two types of VPN client supported inside Windows OS:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;In-built Microsoft VPN client that is created using “Setup a connection or network” in “Network and Sharing Center”. This is also called as GCW client (get connected wizard). This is normally done by end-users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Connection Manager (CM) client created using Connection Manager Administration Kit &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;(CMAK). This is normally created by administrators and then shared to end users via email or upload to a file server or a web server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Note: There may be VPN clients built by 3&lt;SUP&gt;rd&lt;/SUP&gt; party vendors. These 3&lt;SUP&gt;rd&lt;/SUP&gt; party VPN clients can be of two types – first one which calls Microsoft VPN client stack using RAS APIs and second one who install their entire VPN client stack on Windows OS. For sake of simplicity, I am not discussing the behaviour of VPN tunnel strategy by 3&lt;SUP&gt;rd&lt;/SUP&gt; party clients.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Now let us see how the tunnel strategy feature works for both types of clients:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Using in-built VPN client, you can configure following types of tunnel strategy - going inside Connection Properties -&amp;gt; Security tab -&amp;gt; Type of VPN&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Automatic: Try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;PPTP: Try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;L2TP/IPSec: Try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;SSTP: Try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;IKEv2: Try &lt;B style="mso-bidi-font-weight: normal"&gt;VPN Reconnect&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;While creating the CM client, the admin can configure following types of tunnel strategy using CMAK&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;IKEv2 first:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;IKEv2 only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;VPN Reconnect&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;SSTP first: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;SSTP only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;PPTP first: Try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;PPTP only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;L2TP first: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; first – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;IKEv2&lt;/B&gt; next – if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;SSTP&lt;/B&gt; next&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;- if that fails try &lt;B style="mso-bidi-font-weight: normal"&gt;PPTP&lt;/B&gt; last. If that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l2 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;L2TP only: Try &lt;B style="mso-bidi-font-weight: normal"&gt;L2TP/IPSec&lt;/B&gt; and if that fails – stop connection establishment and report error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Please note:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;For a given VPN tunnel type, let us say the tunnel establishment phase succeeds but the entire VPN connection fails - due to authentication issue OR IP address negotiation issue. This doesn’t mean VPN client will try the next tunnel type based upon the tunnel strategy. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;The VPN client tries different tunnel types only if the tunnel establishment fails. This can happen because VPN server is not configured/supports given tunnel type OR packets for a given tunnel type are getting dropped.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;The time it takes to try next tunnel – varies between each tunnel – based upon the retries. For example, IKEv2 tunnel sends 3 retries for first IKEv2 packet spaced at 1, 2 and 4 seconds – hence it will take atleast 7 seconds before next tunnel type is tried. SSTP tunnel takes 10-20 seconds (depending upon the connection is going through a proxy enabled for WPAD or not) to detect failure. And so on.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;If a given tunnel is reachable via IPv4 as well as IPv6 and VPN client is configured with “hostname” of VPN server, then both IPv4 and IPV6 addresses are tried before trying the next tunnel type as given in VPN strategy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;For in-built VPN clients, the last successful VPN tunnel type is tried next time for “Automatic” tunnel type and if that fails it follows the order (as given above) again. However for CM based VPN clients, every VPN connection tries the same order. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Now let us take some deployment scenario:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Assume you have WS2003 VPN servers configured for PPTP and have different VPN users (XP, Vista, Windows 7). And you plan to move users to IKEv2 and SSTP tunnel scenario. You can follow this deployment plan:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level2 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Upgrade all your VPN servers to Windows 7 Server and configure PPTP, SSTP and IKEv2 on the server side.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level2 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Create different CM package for XP and Windows 7.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In the XP package give PPTP only as the VPN Strategy and in W7 package give&amp;nbsp;IKEv2 first as the VPN strategy. Note: W7 package if installed on Vista machine automatically switches to SSTP first (as IKEv2 is not available on Vista).&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 72pt; mso-list: l0 level2 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Send the XP&amp;nbsp; package&amp;nbsp;to XP users and W7 package to Vista + W7 users. And you are all set.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Now as part of deployment plan – you may want to upgrade your VPN servers one-at-a-time. In that case at some point you may be having WS2003 (enabled for PPTP) and Windows 7 server (enabled for PPTP, SSTP, IKEv2) running at the same time. This may mean any client (XP, Vista, Windows 7) may connect to either of the VPN Servers. It should not be a connectivity establishment problem with the above CM package – however Windows 7 users may face “longer connection establishment time” (like 30 seconds) if they connect to Windows 2003 VPN servers &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;as it tries IKEv2 followed by SSTP followed by PPTP.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 18pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;To summarize, the VPN tunnel strategy helps your VPN client to try different tunnel types in a given order and thereby helping you to migrate your remote access users to newer secured tunnel types. Hope this blog helps you in that direction.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;For further references:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx"&gt;&lt;FONT face=Calibri&gt;Different VPN tunnel types in Windows&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2007/06/07/timings-for-transition-from-one-tunnel-type-to-another.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2007/06/07/timings-for-transition-from-one-tunnel-type-to-another.aspx"&gt;&lt;FONT face=Calibri&gt;How automatic tunnel types work in Vista&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;A href="http://blogs.technet.com/rrasblog/archive/2006/11/01/vista-lh-frequently-asked-questions-on-ipv6-support-for-remote-access-scenarios-ras.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2006/11/01/vista-lh-frequently-asked-questions-on-ipv6-support-for-remote-access-scenarios-ras.aspx"&gt;&lt;FONT face=Calibri&gt;Frequently asked Questions on IPv6 support of RAS&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;With Regards,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Samir Jain&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;Windows Networking&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri" lang=EN&gt;&lt;FONT face=Calibri&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3200722" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/SSTP/default.aspx">SSTP</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/PPTP/default.aspx">PPTP</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/L2TP/default.aspx">L2TP</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/Design/default.aspx">Design</category></item><item><title>Do we still need PPTP &amp; L2TP/IPsec after Windows 7</title><link>http://blogs.technet.com/rrasblog/archive/2009/02/10/do-we-still-need-pptp-l2tp-ipsec-after-windows-7.aspx</link><pubDate>Tue, 10 Feb 2009 14:40:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3200123</guid><dc:creator>rrasblog</dc:creator><slash:comments>12</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3200123.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3200123</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Hi Folks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Our team member Samir Jain has posted a nice blog on how you should decide which tunnel to use/deploy for your scenario. The details for the same are given at&amp;nbsp;&lt;A title="Which tunnel to use" href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx"&gt;which tunnel to use&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In this blog, I&amp;nbsp;would like&amp;nbsp;to understand&amp;nbsp;further on a possibility of&amp;nbsp;deprecating PPTP &amp;amp; L2TP/IPsec VPN tunnels&amp;nbsp;going forward - i.e. after Windows 7. This leaves&amp;nbsp;in-the-box Microsoft VPN component&amp;nbsp;supporting SSTP (SSL based )&amp;nbsp;and IKEv2 (IPsec based) VPN tunnel. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Please &lt;STRONG&gt;do not panic&lt;/STRONG&gt;&amp;nbsp;! This has not happened yet.&amp;nbsp;I am just trying to get your feedback and learn more about your deployment plans going forward.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Why do I think you should migrate to IKEv2/SSTP?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;IKEv2 (VPN Reconnect) is a standard based tunnel&amp;nbsp;that should work with any third party servers so interoperability should not be any less if compare to PPTP or L2TP. SSTP allows SSL based firewall traversal thereby supporting ubiquitous VPN connectivity.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Both tunnels are on par or better&amp;nbsp;with L2TP/IPsec&amp;nbsp;as well&amp;nbsp;as PPTP - in terms of security, performance, connection establishment experience etc. &lt;/FONT&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" class=MsoTableGrid border=1 cellSpacing=0 cellPadding=0 class="MsoTableGrid"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: black 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 0.95in; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1" vAlign=top width=91&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;IKEv2&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" vAlign=top width=396&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Does not require client side PKI deployment or pre-shared key.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Integrates well with all EAP based methods&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Leverages the security strength provided by IPsec&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Better in connectivity time compare to L2TP/IPsec&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;5.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Provide mobility switchover support (&lt;A title="mobility manager" href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx"&gt;mobility manager&lt;/A&gt;)&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 113.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1" vAlign=top width=151&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Windows 7 &amp;amp; WS08 R2 onwards&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: black 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 0.95in; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-top-themecolor: text1; mso-border-top-alt: solid black .5pt" vAlign=top width=91&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;SSTP&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" vAlign=top width=396&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Does not require client side PKI deployment or pre-shared key.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Integrates well with all EAP based methods&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Leverages the security strength provided by SSL protocol&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo3; mso-add-space: auto" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Provides firewall traversal&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: black 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 113.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: black 1pt solid; PADDING-TOP: 0in; mso-border-alt: solid black .5pt; mso-border-themecolor: text1; mso-border-left-alt: solid black .5pt; mso-border-left-themecolor: text1; mso-border-top-themecolor: text1; mso-border-top-alt: solid black .5pt; mso-border-bottom-themecolor: text1; mso-border-right-themecolor: text1" vAlign=top width=151&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Vista SP1 &amp;amp; WS08 onwards&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Why we would like to deprecate PPTP/L2TP?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Enables better usability (less #&amp;nbsp;of tunnel choices confusing admins) &amp;amp; better troubleshooting/diagnostics support&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Reduces the support: Reduces the&amp;nbsp;footprint and the number&amp;nbsp;of updates.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Better focus from Microsoft:&amp;nbsp;Our development&amp;nbsp;team can focus mainly on these two tunnels and focus on improving &amp;nbsp;the remote access connectivity experience.&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;I do understand that PPTP is a highly deployed VPN tunnel followed by L2TP/IPSec and Windows 7 will take&amp;nbsp;sometime before&amp;nbsp;it is wide-spread inside organizations (like XP is&amp;nbsp;today).&amp;nbsp;&amp;nbsp;However, we do feel announcing now and deprecating&amp;nbsp;PPTP/L2TP &lt;/FONT&gt;after Windows 7&amp;nbsp; would have provided ample time to our customers to migrate to SSTP (Vista SP1 &amp;amp; WS08 onwards) and IKEv2 (available Windows 7 &amp;amp; WS08 R2 onwards).&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;Again - to re-iterate, there is &lt;STRONG&gt;no official plan in this direction&lt;/STRONG&gt; and this blog post is purely a &lt;STRONG&gt;feedback&amp;nbsp;gaining&amp;nbsp;mechanism&amp;nbsp;&lt;/STRONG&gt;to hear from our enthusiastic&amp;nbsp;remote access&amp;nbsp;customers about&amp;nbsp;their deployment and migration plans to our newer OS supporting exciting new VPN tunnels.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Please share your feedback - either as comment or by&amp;nbsp;sending us an&amp;nbsp;email.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Looking forward to hear back from you&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Cheers,&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Abhishek Tiwari&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Senior Lead Program Manager, &lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;RAS Team, &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Windows Networking&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-ansi-language: EN" lang=EN&gt;&lt;FONT face=Calibri&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3200123" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/SSTP/default.aspx">SSTP</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/PPTP/default.aspx">PPTP</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/L2TP/default.aspx">L2TP</category></item><item><title>Deploying VPN Reconnect: Step-by-step guide available at </title><link>http://blogs.technet.com/rrasblog/archive/2009/02/01/vpn-reconnect-deployment-guide.aspx</link><pubDate>Sun, 01 Feb 2009 19:46:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3195520</guid><dc:creator>rrasblog</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3195520.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3195520</wfw:commentRss><description>&lt;P&gt;Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; The deployment guide for VPN Reconnect is now available at&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;A href="http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc" mce_href="http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc"&gt;&lt;FONT size=3 face="Times New Roman"&gt;http://download.microsoft.com/download/8/9/0/890C2C54-EE49-4743-A5B0-1F3AD7C36721/Step-by-Step_Deploy_Remote_Access_with_VPN_Reconnect.doc&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The guide covers the various requirements for deploying VPN Reconnect and detail steps to configure the various Network Elements. If you have any questions please feel free to post them on this blog or email rrasblog&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&amp;nbsp;&amp;nbsp; Aanand&lt;/SPAN&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3195520" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/How-To/default.aspx">How-To</category></item><item><title>Different VPN tunnel types in Windows - which one to use?</title><link>http://blogs.technet.com/rrasblog/archive/2009/01/30/different-vpn-tunnel-types-in-windows-which-one-to-use.aspx</link><pubDate>Fri, 30 Jan 2009 12:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3194734</guid><dc:creator>rrasblog</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3194734.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3194734</wfw:commentRss><description>&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Hello Folks,&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;I am sure you must have experienced VPN reconnect – a new IKEv2 based VPN tunnel that is added in Windows 7 that allows &lt;SPAN style="mso-bidi-font-family: Calibri; mso-ansi-language: EN; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri" lang=EN&gt;automatic and seamless switchover of an active VPN connection when the underlying Internet interface (connection) changes thus maintaining application persistence&lt;/SPAN&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Isn’t that COOL – like VPN user moving from Wifi to WWAN and back -&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;giving a true mobile connectivity to corpnet ! Yes it is... &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;This means, Windows7 in-built VPN client and Windows 2008 R2 in-built VPN server (aka RRAS) supports following VPN tunnels:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;PPTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;L2TP/IPSec&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;SSTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l1 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;VPN Reconnect (or IKEv2)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;I am sure you must be wondering what is the need for 4 different tunnel types and which one to use in a given scenario. This blog helps to clarify the same.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Let us look at the technical specs which tries to summarize the tunnel features based upon different deployment factors:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;First compare on network related parameters&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid #F79646 1.0pt; mso-border-themecolor: accent6; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" class=MsoTableLightGridAccent6 border=1 cellSpacing=0 cellPadding=0 class="MsoTableLightGridAccent6"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: -1; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-bottom-themecolor: accent6" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 5" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Tunnel Type&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 63.5pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6" vAlign=top width=106&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;OS support&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 54pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6" vAlign=top width=90&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Scenario&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 92.15pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6" vAlign=top width=154&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;IP Addressing&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 60.1pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6" vAlign=top width=100&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Traversal&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 2cm; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6" vAlign=top width=95&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Mobility&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Enabled&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 0"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;PPTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 63.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=106&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;XP, 2003, Vista, WS08, W7, WS08 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 54pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=90&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Remote Access&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Site-to-Site&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 92.15pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=154&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Works over IPv4 network&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 60.1pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=100&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;NAT via PPTP enabled NAT routers&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 2cm; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=95&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;No&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;L2TP/IPSec&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 63.5pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=106&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;XP, 2003, Vista, WS08, W7, WS08 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 54pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=90&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Remote Access&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Site-to-Site&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 92.15pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=154&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Works over IPv4 as well as IPv6 network&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 60.1pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=100&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;NAT&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 2cm; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=95&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;No&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;SSTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 63.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=106&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Vista SP1, WS08, W7, WS08 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 54pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=90&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Remote Access&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 92.15pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=154&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Works over IPv4 as well as IPv6 network&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 60.1pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=100&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;NAT,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Firewalls,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Web Proxy&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 2cm; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=95&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;No&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;VPN Reconnect&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 63.5pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=106&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;W7, WS08 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 54pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=90&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Remote Access&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 92.15pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=154&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Works over IPv4 as well as IPv6 network&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Relay IPv4 as well as IPv6 traffic on top of tunnel&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 60.1pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=100&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;NAT&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 2cm; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=95&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Yes&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Now lets compare on security related parameters &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid #F79646 1.0pt; mso-border-themecolor: accent6; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt" class=MsoTableLightGridAccent6 border=1 cellSpacing=0 cellPadding=0 class="MsoTableLightGridAccent6"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: -1; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-bottom-themecolor: accent6" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 5" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Tunnel Type&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 142.2pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6" vAlign=top width=237&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Authentication&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 99.2pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f79646 1pt solid; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6" vAlign=top width=165&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;Data Confidentiality&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 0"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;PPTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 142.2pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=237&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;User authentication via PPP*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 99.2pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=165&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;RC4***&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;L2TP/IPSec&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 142.2pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=237&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Machine authentication via IPSec &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;followed&lt;/I&gt;&lt;/B&gt;&lt;I style="mso-bidi-font-style: normal"&gt; by&lt;/I&gt; user authentication via PPP*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 99.2pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=165&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;DES, 3DES, AES****&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;SSTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 142.2pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=237&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;User authentication via PPP*&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; PADDING-LEFT: 5.4pt; WIDTH: 99.2pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #fde4d0; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt; mso-background-themecolor: accent6; mso-background-themetint: 63" vAlign=top width=165&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 64" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;RC4, AES&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f79646 1pt solid; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 77.25pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=129&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Cambria','serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-theme-font: major-bidi; mso-ascii-theme-font: major-latin; mso-hansi-theme-font: major-latin"&gt;&lt;FONT size=3&gt;VPN Reconnect&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 142.2pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=237&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Machine &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;or&lt;/I&gt;&lt;/B&gt; user authentication via IKEv2**&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #f79646 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0cm; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 99.2pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #f79646 1pt solid; PADDING-TOP: 0cm; mso-border-bottom-themecolor: accent6; mso-border-top-themecolor: accent6; mso-border-right-themecolor: accent6; mso-border-left-alt: solid #F79646 1.0pt; mso-border-left-themecolor: accent6; mso-border-top-alt: solid #F79646 1.0pt" vAlign=top width=165&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt; mso-yfti-cnfc: 128" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;3DES, AES&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Where,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;* All PPP based &lt;I style="mso-bidi-font-style: normal"&gt;user authentication&lt;/I&gt; supports password (MSCHAPv2) as well as certificate (EAP based user certificate in local store or smart-card) authentication&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;** VPN reconnect supports &lt;I style="mso-bidi-font-style: normal"&gt;machine cert&lt;/I&gt; based authentication as well as &lt;I style="mso-bidi-font-style: normal"&gt;user authentication&lt;/I&gt;&lt;B style="mso-bidi-font-weight: normal"&gt; &lt;/B&gt;which can be password based (EAP-MSCHAPv2) or certificate based (EAP based user certificate in local store or smart-card).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;*** OS prior to Vista supports 40/56/128 bit RC4 encryption for PPTP. Vista onwards supports 128 bit RC4 based encryption only.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;**** OS prior to Vista supports DES, 3DES encryption for L2TP. Vista onwards supports 3DES and AES based encryption.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;U&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Note: All the other features like Winlogon over VPN (aka PLAP), Radius connectivity, NAP based health check continue to be supported on all the VPN tunnels.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Summary&lt;/B&gt;:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;As you can see from the above table, the different deployment factors (like OS choices,&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;PKI infrastructure) and your deployment needs (like support for firewall traversal, support for mobility, need for machine authentication, remote access or site-to-site access)&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;will finally drive your VPN tunnel choice.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;If you will like to simply ignore all technical jargons, &lt;B style="mso-bidi-font-weight: normal"&gt;a simple rule of thumb can be&lt;/B&gt; – &lt;U&gt;use VPN reconnect wherever you can, else configure the fall-back to SSTP&lt;/U&gt;&lt;SPAN style="COLOR: #c00000"&gt;. &lt;/SPAN&gt;This way you will get secured-uninterrupted-ubiquitous VPN connectivity via &lt;I style="mso-bidi-font-style: normal"&gt;IKEv2 tunnel&lt;/I&gt; wherever it is possible (i.e. both endpoint supports IKEv2 and IKEv2 traffic is able to pass through between end-points). Else the VPN connectivity will fall-back to &lt;I style="mso-bidi-font-style: normal"&gt;SSTP tunnel&lt;/I&gt; which can traverse any form of firewalls, NAT, web proxies. In my next post I will discuss further on how the tunnel fallback happens and how to configure the same. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;If you are wondering, why I think VPN reconnect is better compared to L2TP – though both are running on top of IPSec, here is my thinking:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;L2TP/IPSec requires machine authentication followed by user authentication. Assuming no-one uses pre-shared key, this puts a restriction of deploying machine certificates on every L2TP based VPN client machine (i.e. need of PKI infrastructure) – which increases the deployment cost. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt 36pt" class=MsoListParagraph&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;However, VPN reconnect supports simple password based user authentication (EAP-MSCHAPv2), thereby&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;simplifying the deployment&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;VPN reconnect supports IP address persistence in case of underlying link goes down/up or new link comes up – via mobility manager. This way the applications running on top of VPN tunnel sees no break in connectivity (&lt;I style="mso-bidi-font-style: normal"&gt;imagine your big download doesn’t stops in between - if underlying wireless link goes down-up)&lt;/I&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;VPN reconnect is faster in connection establishment phase (less round-trip-times) compared to L2TP/IPSec.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -18pt; MARGIN: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Do you need anything more ....&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Have a happy remote access journey ...&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Cheers,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Samir Jain&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Windows Networking&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;[&lt;SPAN style="mso-ansi-language: EN" lang=EN&gt;This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3194734" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/SSTP/default.aspx">SSTP</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/PPTP/default.aspx">PPTP</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category><category domain="http://blogs.technet.com/rrasblog/archive/tags/L2TP/default.aspx">L2TP</category></item><item><title>Known issues in VPN reconnect mobility manager in Windows 7 beta release</title><link>http://blogs.technet.com/rrasblog/archive/2009/01/30/known-issues-in-vpn-reconnect-mobility-manager-in-windows-7-beta-release.aspx</link><pubDate>Fri, 30 Jan 2009 00:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3194542</guid><dc:creator>rrasblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3194542.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3194542</wfw:commentRss><description>&lt;P&gt;Hi folks,&lt;/P&gt;
&lt;P&gt;Hope you all are in good health.I believe that you must be enjoying the new &lt;A href="http://blogs.technet.com/rrasblog/archive/2009/01/14/vpn-reconnect-a-new-tunnel-for-mobility.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2009/01/14/vpn-reconnect-a-new-tunnel-for-mobility.aspx"&gt;VPN reconnect&lt;/A&gt; feature in Windows 7 and more importantly the mobility experience it provides. Aren't you? I am writing this blog to list the known issues with &lt;A href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx"&gt;mobility manager&lt;/A&gt; and their workarounds. These issues have been fixed in Windows 7 RC milestone.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issues&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Mobility Manager does not start for the first VPN reconnect connection after reboot.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Mobility manager is expected to start as soon as the first mobility enabled VPN reconnect connection is established. This bug is typically seen for the first connection after system boot.&lt;/P&gt;
&lt;P&gt;Workaround:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open taskschd.msc&lt;/LI&gt;
&lt;LI&gt;Navigate to Microsoft\Windows\Ras folder and locate mobility manager task ( as shown &lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/taskscheduler_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/taskscheduler_2.jpg"&gt;here&lt;/A&gt; ).&lt;/LI&gt;
&lt;LI&gt;Right click and start the task by selecting 'Run'.&lt;/LI&gt;&lt;/OL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will keep this blog updated with any new issues found .&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Regards, 
&lt;P&gt;Arpan Kumar Asthana, 
&lt;P&gt;Software Development Engineer, 
&lt;P&gt;Windows Networking Group. &lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3194542" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category></item><item><title>VPN Reconnect: A New Tunnel for Mobility</title><link>http://blogs.technet.com/rrasblog/archive/2009/01/14/vpn-reconnect-a-new-tunnel-for-mobility.aspx</link><pubDate>Wed, 14 Jan 2009 08:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3182187</guid><dc:creator>rrasblog</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3182187.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3182187</wfw:commentRss><description>&lt;P&gt;VPN Reconnect: A New Tunnel for Mobility&lt;/P&gt;
&lt;P&gt;Has your file download or a Line of Business application (LOB) ever got interrupted just because your internet connection went down momentarily and you had to start it all over again ? &lt;/P&gt;
&lt;P&gt;You will never have to do that with the IKEv2 tunnel of “VPN Reconnect” feature available in windows 7.&lt;/P&gt;
&lt;P&gt;Read on to find out what other exciting scenarios can be made possible with VPN reconnect feature.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Look at the following scenarios:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Melissa is a Mobile Information Worker (MIW) who is mostly on the move and uses Wireless Wide Area Network (WWAN) (costly and lower speeds) while she is mobile and Wireless Local Area Network (WLAN)/LAN when at customer locations and when at home or office. As a part of her day to day activities she has to download lots of huge documents from her office server and some LOB applications need uninterrupted connection. As a result she always uses her rather slow and costly WWAN connection even though she has access to high speed WLAN access at different customer locations. She wonders how productive and economical it would have been if she were able to switch to WLAN without her existing applications and downloads getting interrupted.&lt;/P&gt;
&lt;P&gt;Sondra is a release manager of a software company whose offices are distributed across different cities and she has to regularly talk to different project teams across different cities as a part of her day to day job. To reduce long distance telephone costs her company has decided to use Voice call over Office communicator instead of long distance calls over cellphones. While she appreciates the clarity of voice she gets using office communicator, she rues the fact that calls get disconnected as he moves between meeting in different buildings and the WiFi access points change. She wonders if should could have the same roaming feature with office communicator as she has with traditional cell phones.&lt;/P&gt;
&lt;P&gt;Ichiro is a network admin of an Internet service provider contoso.com Contoso.com does not own any physical infrastructure but leases internet connectivity from different regional service providers and give a single country wide solution to all its customers. The reason contoso’s service offers more value for the money is because they will be able harness the cheapest internet service available in that region. If a particular city has low cost WLAN encompassing all areas, contoso’s customers can connect to this WiFi service instead of the costly WWAN service. One complaint contoso has from its customers is that whenever the local service provider changes, the IP address of the customers changes and all their applications get disconnected. Contoso cannot use Mobile IP as it does not own the network infrastructure. Contoso is looking for a simple solution for this problem&lt;/P&gt;
&lt;P&gt;IKEv2 tunnel of VPN Reconnect solves above scenarios and the problems whenever the underlying network changes. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;How it works:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;VPN Reconnect is built on IPsec Tunnel Mode (&lt;A href="http://www.ietf.org/rfc/rfc4301.txt" mce_href="http://www.ietf.org/rfc/rfc4301.txt"&gt;RFC 4301&lt;/A&gt;) that uses IKEv2 (&lt;A href="http://www.ietf.org/rfc/rfc4306.txt" mce_href="http://www.ietf.org/rfc/rfc4306.txt"&gt;RFC 4306&lt;/A&gt;) for key negotiation and transmits ESP (&lt;A href="http://www.ietf.org/rfc/rfc4303.txt" mce_href="http://www.ietf.org/rfc/rfc4303.txt"&gt;RFC 4303&lt;/A&gt;) packets. MOBIKE (&lt;A href="http://www.ietf.org/rfc/rfc4555.txt" mce_href="http://www.ietf.org/rfc/rfc4555.txt"&gt;RFC 4555&lt;/A&gt;) is used to switch the tunnel end points when the underlying interface changes.&lt;/P&gt;
&lt;P&gt;The following diagram illustrates a scenario of VPN Reconnect.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image002%5B4%5D.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image002%5B4%5D.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image002[4] border=0 alt=clip_image002[4] src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image002%5B4%5D_thumb.jpg" width=244 height=119 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image002%5B4%5D_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The mobile user initially connects to an IKEv2 compatible server to access corpnet over Wired LAN. &lt;/P&gt;
&lt;P&gt;The user then starts using a client application that communicates with the application servers in the corporate network. Now if the user disconnects his wired LAN connection and connects to WiFi hotspot his VPN connection persists and his client application continues its communication with the application server un-interrupted. Let us see how to achieve this and how it works&lt;/P&gt;
&lt;P&gt;Configuring IKEv2 Client:&lt;/P&gt;
&lt;P&gt;1. Specifying the VPN server address /name:&lt;/P&gt;
&lt;P&gt;In the general tab of RAS connectoid properties, specify the VPN server destination. You can specify the IPv4 address, IPv6 address or the Fully Qualified Domain Name (FQDN) of the VPN server .&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image004%5B4%5D.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image004%5B4%5D.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image004[4] border=0 alt=clip_image004[4] src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image004%5B4%5D_thumb.jpg" width=193 height=244 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image004%5B4%5D_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2. Specifying the tunnel options:&lt;/P&gt;
&lt;P&gt;On the security tab select IKEv2 from the dropdown menu of Type of VPN&lt;/P&gt;
&lt;P&gt;VPN Reconnect supports different encryption options ranging from no encryption to AES256.&lt;/P&gt;
&lt;P&gt;VPN Reconnect supports two types of Authentication: &lt;/P&gt;
&lt;P&gt;a. Extensible Authentication Protocol (EAP)(RFC 3748)&lt;/P&gt;
&lt;P&gt;b. X.509 Machine Certificates (RFC 2459)&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image006%5B4%5D.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image006%5B4%5D.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image006[4] border=0 alt=clip_image006[4] src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image006%5B4%5D_thumb.jpg" width=202 height=244 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image006%5B4%5D_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3. Enabling Mobility:&lt;/P&gt;
&lt;P&gt;In the advanced properties tab there is a Mobility check box. By default this check box is enabled for VPN Reconnect. If the check box is unchecked the client cannot switch its local tunnel endpoint.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image008%5B4%5D.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image008%5B4%5D.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image008[4] border=0 alt=clip_image008[4] src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image008%5B4%5D_thumb.jpg" width=244 height=173 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image008%5B4%5D_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;4. Selecting IPv4 and IPv6&lt;/P&gt;
&lt;P&gt;VPN Reconnect supports both IPv4 and IPv6 internal addresses. &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image010_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image010_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image010 border=0 alt=clip_image010 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image010_thumb.jpg" width=190 height=244 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image010_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;5. Connecting:&lt;/P&gt;
&lt;P&gt;Once the configuration is done all you need to do is click connect.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image012_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image012_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image012 border=0 alt=clip_image012 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image012_thumb.jpg" width=244 height=187 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image012_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;6. Status:&lt;/P&gt;
&lt;P&gt;On the details tab of the status page of the connection. The local and remote addresses are shown.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image014_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image014_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image014 border=0 alt=clip_image014 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image014_thumb.jpg" width=202 height=244 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image014_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In the above page the vpn connection is over the interface “ Local Area Connection” with IP address 172.23.90.42. The Destination address of the VPN server is 172.23.90.71.&lt;/P&gt;
&lt;P&gt;The Client IPv4 address 172.23.90.89 is the address to which all the application sockets bind to. VPN Reconnect makes sure that even if the Origin address changes the Client Internal IPv4 address remains same and hence the connection is persisted.&lt;/P&gt;
&lt;P&gt;When the LAN interface goes down, &lt;A href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx"&gt;mobility manger&lt;/A&gt; switches to the next available interface, in the diagram below the new interface is “Wireless Network Connection” with IP address 10.86.52.186.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image016_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image016_2.jpg"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image016 border=0 alt=clip_image016 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image016_thumb.jpg" width=203 height=244 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/VPNReconnectANewTunnelforMobility_A0B7/clip_image016_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can observer that in both the cases the Client Ipv4 address did not change and remained same 172.23.90.89 as a result the applications that bind to 172.23.90.89 will not see any change in the interface going down and hence all the applications are persisted.&lt;/P&gt;
&lt;P&gt;Variations:&lt;/P&gt;
&lt;P&gt;In addition to the above illustrations VPN Reconnect persists the connection the following scenarios as well:&lt;/P&gt;
&lt;P&gt;Switch from IPv4 to IPv6 address&lt;/P&gt;
&lt;P&gt;If the server and client have both IPv4 and IPv6 connectivity, the client can first connect over IPv6 Internet address and switch to an IPv4 Internet address and vice-versa.&lt;/P&gt;
&lt;P&gt;Switch from Internet to Corpnet&lt;/P&gt;
&lt;P&gt;If the client first connects to corpnet from Internet and then connects to corpnet, VPN Reconnect switches the VPN connection from the Internet facing address of the server to the Internal corpnet address of the server. So if a user starts a voice conversation using Office Communicator over VPN when connected to the internet, he can continue the conversation without any interruption as he walks into his office and connects to Corporate network. This possible even if the corporate network firewall does not allow IKE/ESP packets going out of its Internet gateway because &lt;A href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx" mce_href="http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx"&gt;mobility manger&lt;/A&gt; tries all combinations of VPN server internal and external addresses when the underlying network goes down. &lt;/P&gt;
&lt;P&gt;Switching when the IP Address of an Interface changes&lt;/P&gt;
&lt;P&gt;If the IP address of an interface changes, VPN Reconnect ensures that the connection is persisted. So if user connects to his corporate network over WiFi network, his VPN connection stays up even if his WiFi access points change and the IP address of this WiFi interface changes. &lt;/P&gt;
&lt;P&gt;Persistent Connection amidst frequent disconnections&lt;/P&gt;
&lt;P&gt;If you have a lossy WWAN connection with frequent disconnections and you are want to watch streaming media, every time the connection gets disconnected you will have to re-start the streaming and the buffered data is lost. With IKEv2 tunnel if the WWAN connection gets disconnected and reconnected (even with a new IP address) the connection persists and streaming downloads get resumed for the point of disconnect.&lt;/P&gt;
&lt;P&gt;Uma Mahesh Mudigonda&lt;/P&gt;
&lt;P&gt;Developer, Routing &amp;amp; Remote Access&lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3182187" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category></item><item><title>The Mobility Manager - managing mobility for VPN reconnect connections (IKEv2 based VPN connections) </title><link>http://blogs.technet.com/rrasblog/archive/2008/12/31/the-mobility-manager-managing-mobility-for-agile-vpn-connections.aspx</link><pubDate>Tue, 30 Dec 2008 22:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3174834</guid><dc:creator>rrasblog</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/rrasblog/comments/3174834.aspx</comments><wfw:commentRss>http://blogs.technet.com/rrasblog/commentrss.aspx?PostID=3174834</wfw:commentRss><description>&lt;P&gt;Hi folks, 
&lt;P&gt;It's again that exciting time of the year when the next version of Windows is going to make it to the markets. Win7 boasts of several cool features that promise to transform the lives of people and make computers more effective and easier to use. So are you ready to grab a glimpse of these cool features that highlight Win7? 
&lt;P&gt;Present VPN tunnels do not provide mobility support. By mobility I mean that if the interface on which the VPN connection is established, gets disconnected, your VPN connection gets disconnected too. You have to re-dial the connection over the next available interface and undergo the time consuming authentication process and security checks. This leads to waste of your time, puts undue burden on the VPN servers and causes annoyance. Isn't it? Now imagine if there is some mechanism by which the switch is automatically performed to the next available Internet capable interface and the same VPN connection stays as it is. Excited? This is exactly what we are trying to achieve through this new component. Let me introduce you to the Mobility manager. It is a component which seamlessly switches over the VPN connection (VPN connection hereafter refers to a connection using new VPN tunnel called IKEv2) to next available interface, when the lower layer interface gets disconnected. In this post I will go through the general behavior, configuration, scenarios and limitations of this component. So let's get started!!! 
&lt;P&gt;Mobility manager primarily targets a roaming user and provides her continuous corporate connectivity when she moves across various networks. It also provides for seamless switching of a VPN connection from one interface to another when the interface, on which the VPN connection is established, goes down, hence providing continuous connectivity to a static user also. Some of the real life scenarios can be - 
&lt;OL&gt;
&lt;LI&gt;A connected user remains connected when she moves across wireless access points (coffee shops/hotels).&lt;/LI&gt;
&lt;LI&gt;A user connected from &lt;B&gt;home&lt;/B&gt; (through WWAN/GPRS) remains connected when she comes inside the corporate network (i.e. comes to office).&lt;/LI&gt;
&lt;LI&gt;A connected user remains connected if the underlying interface goes down and some other interface (with network connectivity) is available.&lt;/LI&gt;
&lt;LI&gt;A connected user remains connected if the underlying interface is flaky. In this case other VPN connections get disconnected, but the IKEv2 based VPN connection stays up.&lt;/LI&gt;
&lt;LI&gt;A connected user remains connected if she moves from an IPv4 enabled network to an IPv6 enabled network and vice versa, provided the server supports IPv6 addresses.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;One major characteristic of the switchover is that during the switchover the IKEv2 connection is itself not redialled or re-authenticated, only the external endpoints change.So you need not redial the connection and re-enter your credentials. After the switch is performed, the VPN tunnel will start using the new interface. The applications using this connection see no change and continue to work the same way as before without breaking. That's what you call a seamless switch, isn't it? 
&lt;P&gt;&lt;B&gt;&lt;U&gt;How to make your VPN connection mobility enabled&lt;/U&gt;&lt;/B&gt; 
&lt;P&gt;Follow the following steps to make an IKEv2 based VPN connection mobility enabled 
&lt;OL&gt;
&lt;LI&gt;Open VPN connectoid properties&lt;/LI&gt;
&lt;LI&gt;Go to the security tab&lt;/LI&gt;
&lt;LI&gt;Click on Advanced Settings.&lt;/LI&gt;
&lt;LI&gt;Check the mobility checkbox to enable mobility.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/EnableMobility_2.png" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/EnableMobility_2.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; BORDER-TOP: 0px; BORDER-RIGHT: 0px" border=0 alt=EnableMobility src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/EnableMobility_thumb.png" width=313 height=344 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/EnableMobility_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;Behavior of Mobility manager&lt;/U&gt;&lt;/B&gt; 
&lt;P&gt;IKEv2 based VPN connection exhibits three states- 
&lt;OL&gt;
&lt;LI&gt;Connected&lt;/LI&gt;
&lt;LI&gt;Dormant - When the underlying interface through which IKEv2 is connected to the corporate network goes down/ or the access point changes.&lt;/LI&gt;
&lt;LI&gt;Waiting to reconnect - When the mobility manager is trying to switch the connection to the next available interface or access point.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;These states can be explained with an example. Consider a scenario when you are home with a IKEv2 based VPN connection to corporate network over a broadband (PPPoE ) connection. Also assume you have a disabled wireless network that can also provide Internet connectivity. 
&lt;UL&gt;
&lt;LI&gt;Initially the VPN connection is connected.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image004_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image004_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; BORDER-TOP: 0px; BORDER-RIGHT: 0px" border=0 hspace=12 alt=clip_image004 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image004_thumb.jpg" width=244 height=30 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image004_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Now if the broadband connection gets disconnected ( and with wireless disabled) , the VPN connection goes into a dormant state as shown below&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image006_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image006_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; BORDER-TOP: 0px; BORDER-RIGHT: 0px" border=0 hspace=12 alt=clip_image006 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image006_thumb.jpg" width=244 height=25 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image006_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Now if you enable the wireless network, the mobility manager tries to switchover the VPN connection over the wireless network. While the switchover is in progress, the VPN connection is in a 'waiting to reconnect' as shown below&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image008_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image008_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; BORDER-TOP: 0px; BORDER-RIGHT: 0px" border=0 hspace=12 alt=clip_image008 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image008_thumb.jpg" width=244 height=25 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image008_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;After a successful switchover the VPN connection is happily reconnected.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image009_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image009_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; BORDER-TOP: 0px; BORDER-RIGHT: 0px" border=0 hspace=12 alt=clip_image009 src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image009_thumb.jpg" width=244 height=30 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/clip_image009_thumb.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Some points to note about mobility manager's behavior- 
&lt;OL&gt;
&lt;LI&gt;The dormant VPN connection will start using a new Internet capable interface in a few milliseconds.&lt;/LI&gt;
&lt;LI&gt;In case no new Internet capable interface is available on the system, mobility manager performs a switch as soon as one is available.&lt;/LI&gt;
&lt;LI&gt;In case system has no network connectivity and there are dormant connections on the system, mobility manager tries to switch the dormant connections at regular intervals.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;B&gt;&lt;U&gt;Troubleshooting mobility manager&lt;/U&gt;&lt;/B&gt; 
&lt;P&gt;Mobility manager runs as a task having local service privileges. It gets triggered when the first mobility enabled IKEv2 connection is connected and continues to run till there is one available. It can manage any number of IKEv2 connections on the system. 
&lt;P&gt;Mobility manager is a robust and reliable component and typically user would not face any issues, but in case some problem happens , you can do the following checks 
&lt;OL&gt;
&lt;LI&gt;Check if mobility manager is running-&lt;/LI&gt;&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;Run taskschd.msc&lt;/LI&gt;
&lt;LI&gt;Open \Microsoft\Windows\Ras task and verify that mobility manager is running.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/taskscheduler_2.jpg" mce_href="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/taskscheduler_2.jpg"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; BORDER-TOP: 0px; BORDER-RIGHT: 0px" border=0 alt=taskscheduler src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/taskscheduler_thumb.jpg" width=372 height=399 mce_src="http://blogs.technet.com/blogfiles/rrasblog/WindowsLiveWriter/TheMobilityManagermanagingmobilityforagi_133A/taskscheduler_thumb.jpg"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.&amp;nbsp;&amp;nbsp; Enable log collection: &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; To enable logs, run the following command from the administrator command prompt.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; netsh ras diagnostics set tracefacilities enabled&lt;U&gt;&lt;/U&gt;&lt;/B&gt; 
&lt;P&gt;&lt;B&gt;&lt;U&gt;Limitations&lt;/U&gt;&lt;/B&gt; 
&lt;P&gt;Some of the downsides of Mobility manager can be - 
&lt;OL&gt;
&lt;LI&gt;No provision for cost based switching. User cannot specify the costs associated with the interfaces. One crude way to specify cost is manually setting the interface metric instead of automatic setting.&lt;/LI&gt;
&lt;LI&gt;It only supports make after break scenarios meaning that a switch is performed only if the current IKEv2 based VPN connection becomes dormant.&lt;/LI&gt;&lt;/OL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Regards, 
&lt;P&gt;Arpan Kumar Asthana, 
&lt;P&gt;Software Development Engineer, 
&lt;P&gt;Windows Networking Group. &lt;/P&gt;
&lt;SCRIPT type=text/javascript&gt;
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
&lt;/SCRIPT&gt;

&lt;SCRIPT type=text/javascript&gt;
try {
var pageTracker = _gat._getTracker("UA-1700161-11");
pageTracker._trackPageview();
} catch(err) {}&lt;/SCRIPT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3174834" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/rrasblog/archive/tags/IKEv2/default.aspx">IKEv2</category></item></channel></rss>