<?xml version="1.0" encoding="utf-8"?>
				<!-- generator="e107" -->
				<!-- content type="Forum / threads" -->
				<rss  version="2.0" 
					xmlns:content="http://purl.org/rss/1.0/modules/content/" 
					xmlns:atom="http://www.w3.org/2005/Atom"
					xmlns:dc="http://purl.org/dc/elements/1.1/"
					xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"

				>
				<channel>
				<title>Dimante Computer Services LLC : Forum / threads</title>
				<link>http://www.dimante.net/</link>
				<description></description>

<language>en-gb</language>
				<copyright>All site content and theme is (C)2007-2011 Dimante Computer Services LLCThe Link Exchange - Your ultimate resource for link exchange!</copyright>
				<managingEditor>dimante@nospam.com (Dimante)</managingEditor>
				<webMaster>dimante@nospam.com (Dimante)</webMaster>
				<pubDate>Sat, 19 May 2012 18:16:32 -0500</pubDate>
				<lastBuildDate>Sat, 19 May 2012 18:16:32 -0500</lastBuildDate>
				<docs>http://backend.userland.com/rss</docs>
				<generator>e107 (http://e107.org)</generator>
				<sy:updatePeriod>hourly</sy:updatePeriod>
				<sy:updateFrequency>1</sy:updateFrequency>

				<ttl>60</ttl>
<atom:link href="http://mail.dimante.net/e107_plugins/rss_menu/rss.php?forumthreads.2" rel="self" type="application/rss+xml" />

					<image>
					<title>Dimante Computer Services LLC : Forum / threads</title>
					<url>http://mail.dimante.net/e107_images/dcs_Server.gif</url>
					<link>http://www.dimante.net/</link>
					<width>88</width>
					<height>31</height>
					<description></description>
					</image>
<item>
<title>UseBB to Vanilla Conversion Script</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?19</link>
<description><![CDATA[Do you have a UseBB database that you want to convert to Vanilla? No problem!<br /><br /> <a class='bbcode' href='http://www.dimante.net/migrator.tgz' rel='external' >Get the script here</a> <br /><br />Post any questions or problems here.<br />-D-]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Wed, 23 Apr 2008 12:35:30 -0500</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?19</guid>
</item>

<item>
<title>Identify Errors using the NCP Log</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?18</link>
<description><![CDATA[NCP Secure Enterprise Client	8.10<br />NCP Secure Enterprise Linux Client	2.01<br />NCP Secure Enterprise CE Client	2.0x<br />NCP Secure Entry Client	8.12<br />Troubleshooting the IPsec connection can be intimidating at first, but if one knows what to look for, things aren't as daunting as they would seem.<br /><br />First of all, lets have a look at the log file:<br /><br />Extended Firewall: is stopped<br />Warning: could not open file - c:&#092;crypt.key<br />Found adapter: ASYNCMAC1 with MTU 1500 bytes<br />Found adapter: PRISM1 with MTU 1500 bytes<br />Installed as a test license.<br /><br />The first line will indicate the status of the personal firewall.<br />The second line regarding crypt.key can safely be ignored.<br />Then follows a listing of all available network interfaces the client has detected that can be used.<br />Followed by the status of the license, in this case, it's a test license that will expire within 30 days.<br /><br />This entry in the knowledge base will not cover the connection to the ISP, but concentrate on building the IPSec VPN tunnel.<br /><br />IPSDIAL::DNSREQ: resolving dnserver over provider: myvpngateway.example.com<br />IPCP - connected to with IP Address: 062.123.044.037. : 146.007.073.242.<br />IPSDIAL->DNSREQ: resolved ipadr: 198.147.245.21<br /><br />In this example, the VPN gateway has not been configured as an IP address, but as a FQDN, so the first step the client does is resolve the name to an IP address so the VPN gateway can be reached.<br />Then the client will attempt to make a connection:<br /><br />NCPIKE-phase1:name() - outgoing connect request -main mode.<br />XMIT_MSG1_MAIN -<br /><br />We see it's a Main Mode connection. If the client does not proceed past this point, please refer to the table below. To understand the table, one needs to know what it is that is transmitted within this first message. By way of example, we'll look at this first transmission: XMIT_MSG1_MAIN contains the Proposals and Vendor IDs. If it fails here, it's most likely that the tunnel endpoint is not available, wrong IKE proposals have been selected or the wrong connection mode has been selected. Steps can be taken to verify the VPN gateway is online. Furthermore check that the proposals match that what the VPN gateway expects<br />(Note: "automatic mode" does not support proposals with 'mere' DES, if DES is used, please manually define a proposal. If proposals using 3DES or AES are used, then "automatic mode" will generally work.)<br />The Vendor IDs sent here also tells the VPN gateway what modes the Client supports; such as XAUTH, IKE-CFG, and NAT-T. In this example, only NAT-T is negotiated.<br /><br />RECV_MSG2_MAIN -<br />IKE phase I: Setting LifeTime to 28800 seconds<br />->Support for NAT-T version - 3<br /><br />Gateway returns with a confirmation that NAT -T is going to be used and this is negotiated. One would not expect an error to occur after this step<br /><br />XMIT_MSG3_MAIN -<br />IPSDIAL->FINAL_TUNNEL_ENDPOINT:198.147.245.21<br />RECV_MSG4_MAIN -<br />Turning on NATD mode - - 2<br /><br />NAT-T is now enabled. Errors don't usually happen after 3rd message. Had a certificate been used, and the it wasn't available, the log may have stopped here and the connection attempt aborted.<br /><br />XMIT_MSG5_MAIN -<br /><br />Had the log stopped after this step, then one would look in the table and see that it could be that the IKE-ID (see the Identities section in the configuration paramaters) type, or pre-shared key was incorrect, or when using a certificate, there was an error with the certificates. Another possible cause is that NAT-T has been negotiated as shown above, which means that traffic will now be encapsulated within UDP4500 datagrams and possibly there is a firewall that's prohibiting the datagrams from reaching the VPN gateway.<br />(Note:: NCP Secure Clients do NOT support TCP encapsulation)<br /><br />RECV_MSG6_MAIN -<br />NCPIKE-phase1:name() - connected<br /><br />Phase One has successfully negotiated. If XAUTH and IKE-CFGmode were used, they would be negotiated here before proceeding to Phase Two.<br />Phase Two is also referred to as Quick Mode.<br /><br />XMIT_MSG1_QUICK -<br /><br />This is often a point where confusion arrises. When IKE-ConfigMode is not used, one needs to define the ID1 and ID2.<br />ID1 is the IP address the client is going to be known as, this could be the local IP address it has, or a virtual IP address that's been 'assigned' but not pushed to the client by the VPN gateway. (The latter happens when using IKE-CFGMode).<br />ID2 are the networks that the client is going to reach. Some gateways are more particular about this than others. These "remote networks" can also be individual hosts, or network ranges. Pay special attention to defining the netmasks correctly as well.<br />Another common mistake is the incorrect definition of the PFS Group that is going to be used.<br /><br />RECV_MSG2_QUICK -<br />XMIT_MSG3_QUICK -<br />NCPIKE-phase2:name() - connected<br />IPSDIAL - connected to on channel 1.<br />IPCP - connected to with IP Address: 010.000.000.010. : 010.000.000.011.<br /><br />And here a connection has been made, confirmed by the presenting of the IP addresses the client is going to use.<br /><br />Please note that in the table below there may be differences depending on whether one uses a certificate (RSA) to authenticate, or if pre-shared keys (PSK) are used.<br /><br />Message / Sequence<br />	Content<br />	Possible error<br />MAIN MODE (PHASE 1)<br />XMIT_MSG1_MAIN 	PROP, [VID] 	Tunnel Endpoint (Not reachable),<br />IKE proposals,<br />Mode (Aggressive)<br />RECV_MSG2_MAIN 	PROP, [VID] 	Internal Error<br />XMIT_MSG3_MAIN 	KE, N, [NAT-D] 	Communication Error<br />RECV_MSG4_MAIN 	KE, N, [NAT-D] 	RSA: 	PKI-error (no certificate or incorrect PIN)<br />XMIT_MSG5_MAIN 	ID, [CERT], HASH/SIG 	PSK &amp; RSA:<br />	Invalid IKE-ID,<br />NAT-T enabled, but firewall blocking it (UDP4500)<br />PSK:<br />	Invalid PSK<br />RSA:<br />	PKI-error (local or remote)<br />RECV_MSG6_MAIN 	ID, [CERT], HASH/SIG 	PSK:<br />	Invalid HASH (problem with the PSK)<br />RSA:<br />	PKI-error, invalid signature<br />AGGRESSIVE MODE (PHASE 1)<br />XMIT_MSG1_AGGR 	PROP, KE, N, ID, [VID]<br />	Tunnel Endpoint not reachable<br />IKE proposals<br />Mode (Main)<br />Invalid IKE-ID<br />RECV_MSG2_AGGR 	PROP, KE, N, ID, [VID], [NAT-D], [CERT], HASH<br />	PSK:<br />	Invalid PSK<br />RSA:<br />	PKI-error (local), Invalid signature<br />Invalid signature<br />XMIT_MSG3_AGGR<br />	HASH, [CERT], [NAT-D]<br />	PSK &amp; RSA:<br />	NAT-T enabled, but firewall blocking it (UDP4500)<br />Waiting for XAUTH<br />RSA:<br />	PKI-error (remote)<br /><br />Message / Sequence<br />	Content<br />	Possible error<br />IPSEC "QUICK MODE" (PHASE 2)<br />XMIT_MSG1_QUICK 	HASH, PROP, [KE], N, ID1 &amp; ID2 	Invalid proposals, invalid ID1 or ID2 (also check Compression &amp; PFS!)<br />RECV_MSG2_QUICK 	HASH, PROP, [KE], N, ID1 &amp; ID2 	Illegal Hash<br />XMIT_MSG3_QUICK 	HASH 	Remote doesn't like my HASH<br /><br /><br />Used Acronyms<br />PROP<br />	Proposal<br />	HASH<br />	Hash< br>VID<br />	Vendor ID<br />	SIG<br />	Signature<br />KE<br />	Key Exchange<br />	ID1<br />	Source / Local IP Address<br />N<br />	Nonce<br />	ID 2<br />	Destination Network(s) / Host(s)<br />NAT-D<br />	Network Address Translation Detection<br />	IP-COMP<br />	IP Compression<br />ID<br />	IKE-ID "Identity"<br />	PFS<br />	Perfect Forward Secrecy<br />CERT<br />	x509v3 Certificate<br />	<br />	<br /><br /><br /><br />Disclaimer<br />Considerable care has been taken in the preparation of this document, errors in content, typographical or otherwise may occur. If you have any comments or recommendations concerning the accuracy, then please contact NCP as desired.<br />NCP makes no representations or warranties with respect to the contents or use of this document, and explicitly disclaims all expressed or implied warranties of merchantability or use for any particular purpose. Furthermore, NCP reserves the right to revise this publication and to make amendments to the content, at any time, without obligation to notify any person or entity of such revisions and changes.<br /><br />Trademarks<br />All trademarks or registered trademarks appearing in this manual belong to their respective owners.<br /><br />© 2005 NCP Engineering GmbH. All rights reserved.]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Sat, 05 Apr 2008 02:58:46 -0500</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?18</guid>
</item>

<item>
<title>Openswan/Freeswan &amp; NCP Secure Client</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?17</link>
<description><![CDATA[A lot of customers opt to use their existing Open/Freeswan VPN Servers in conjunction with our VPN Client, and this is no problem. Please bear in mind that NCP also provides an IPsec and feature rich VPN gateway ("Secure Server") for Linux (SuSE &amp; RedHat / Fedora)<br /><br />You may also be interested to know that we have the same client available for Linux platforms (primarily SuSE and RedHat/Fedora), as well as for PDAs running on PocketPC2002/3.<br /><br />Below there's an example configuration (which is to be used as a starting point, please refer to the URLs listed at the end of the document for further information on how to implement other features as this is by no means a 'full configuration'). In this test set up, the VPN server "vpn-gw01" is listening on 22.23.24.25. (Please also have a look at a document on our website with how to configure the client: http://www.ncp.de/fileadmin/pdf/service_support/NCP_QCG_Entry_Client_VPNC.pdf)<br /><br />The items within the < and > are variables you need to enter, such as passwords. This configuration assumes you're using certificates as a basis to authenticate with. Unfortunatly there isn't an example on how to configure it with the use of pre-shared keys. If you are not familiar with how to create the certificates, please refer to the http://www.natecarlson.com/linux/ipsec-x509.php#gencert which nicely outlines how to do this on a Linux box.<br /><br /><br />Two files that need to be configured: ipsec.secrets and ipsec.conf<br /><br />[root@vpn-gw01]# less /etc/ipsec.secrets<br />#<br /># IPSEC SECRET FILE<br />#<br />%any 22.23.24.25 : RSA vpngw.key ""<br />#<br /><br />[root@vpn-gw01]# less /etc/ipsec.conf<br /># /etc/ipsec.conf - Openswan IPsec configuration file<br />version 2.0 # conforms to second version of ipsec.conf specification<br /><br /># basic configuration<br />config setup<br />interfaces=ipsec0=eth1<br />#interfaces=%defaultroute<br />nat_traversal=yes<br />virtual_private=%v4:x.x.x.x/24 # x.x.x.x internal network<br /># Debug-logging controls: "none" for (almost) none, "all" for lots.<br /># klipsdebug=none<br />plutodebug="control parsing"<br /><br /># Add connections here<br />conn %default<br />keyingtries=1<br />compress="no" #this should now be supported: so "yes" is possible<br /><br />disablearrivalcheck=no<br />authby=rsasig<br />leftrsasigkey=%cert<br />rightrsasigkey=%cert<br />left=22.23.24.25<br />leftcert=vpngw.pem #vpngw.pem is the server's certificate<br /><br />conn roadwarrior-net<br />leftsubnet=x.x.x.x/24 # x.x.x.x internal network<br />also=roadwarrior<br /><br />conn roadwarrior-all<br />leftsubnet=0.0.0.0/0<br />also=roadwarrior<br /><br />conn roadwarrior<br />right=%any<br />rightsubnet=vhost:%no,%priv<br />auto=start<br />pfs=yes<br /><br />include /etc/ipsec.d/examples/no_oe.conf<br /><br />[root@vpn-gw01 /]#<br /><br /><br />Other links that may be helpful:<br />http://www.openswan.org/docs/local/README.x509 &<br />http://wiki.openswan.org<br />/index.php/Configuring &<br />http://www.natecarlson.com/linux/ipsec-x509.php#configgw<br /><br /><br />Disclaimer<br />Considerable care has been taken in the preparation of this document, errors in content, typographical or otherwise may occur. If you have any comments or recommendations concerning the accuracy, then please contact NCP as desired.<br />NCP makes no representations or warranties with respect to the contents or use of this document, and explicitly disclaims all expressed or implied warranties of merchantability or use for any particular purpose. Furthermore, NCP reserves the right to revise this publication and to make amendments to the content, at any time, without obligation to notify any person or entity of such revisions and changes.<br /><br />Trademarks<br />All trademarks or registered trademarks appearing in this manual belong to their respective owners.<br /><br />© 2005 NCP Engineering GmbH. All rights reserved.]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Sat, 05 Apr 2008 02:53:31 -0500</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?17</guid>
</item>

<item>
<title>SonicWALL Pro 200 / SOHO Configuration</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?15</link>
<description><![CDATA[<div class=Section1><strong><span style='font-size:14px'>SonicWALL PRO 200 / SOHO VPN Setup Instructions for use with NCP Secure Client</span> </strong>  <p align="left"> </p>  <p align="left"><span style='font-size:10px'><span style='color:#ff0000'>IMPORTANT NOTE:</span> <strong class='bbcode bold'>The NCP Client (or derivative thereof, also referred to as NCP Client in this document) cannot co-exist with another VPN Client, so it<br />is imperative that other VPN clients have been removed before<br />proceeding. You will be able to use the NCP VPN Client to establish<br />connections to many other VPN Gateways, and are by no means locked down to only using specific vendor's VPN gateways.</strong></span> </p>  <h1 align="left" class="Section1">SonicWALL Setup </h1>  <p align="left"><strong class='bbcode bold'>Click on the VPN button on the left and the following is displayed:</strong></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image002.jpg" width="400"></p><br /> <p align="left"><strong class='bbcode bold'>Write the Firewall Unique Identifier down (You will need this later in the NCP setup).</strong></p>  <p align="left"><strong class='bbcode bold'>Click on “Configure”</strong></p><br /><p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image004.jpg" width="400""></p><br /> <p align="left"><strong class='bbcode bold'>Set a shared secret on this page. Make note of this also for the NCP client setup later in this post. </strong></p>  <p align="left"><strong class='bbcode bold'>Click advanced:</strong></p><br /><p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image006.jpg" width="400"></p><br /> <p align="left"><strong>IMPORTANT: Make sure perfect forward secrecy is checked.</strong>              </p>  <p align="left"> </p>  <h1 align="left">NCP Secure Client Configuration </h1>  <p align="left"><strong class='bbcode bold'>Next we will configure the NCP client for connection:</strong></p>  <p align="left"><strong class='bbcode bold'>In the NCP Client click Configuration > Profile Settings</strong></p>  <p align="left"><strong class='bbcode bold'>Choose New Entry and follow each of the prompts with what is displayed below: </strong></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image008.jpg" width="400"></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image010.jpg" width="400"></p><br /> <p align="left"><strong class='bbcode bold'>Give the connection a freindly name so that you can easily identify it.</strong> </p><br /><p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image012.jpg" width="400"></p><br /> <p align="left"><strong class='bbcode bold'>The LAN selection is proper for most installations. If you use ISDN or Dial up then<br /> you will need to make a different choice above.</strong> </p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image014.jpg" width="400"></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image016.jpg" width="400"></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image018.jpg" width="400"></p><br /> <p align="left"><strong class='bbcode bold'>Enter your shared secret that you recoded earlier and repeat it in the confirm box to<br /> the left. For local identity put the unique identifier in that you recorded in the SonicWALL<br /> setup section. </strong></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image020.jpg" width="400"></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image022.jpg" width="400"></p><br /> <p align="left"><strong class='bbcode bold'>Click Finish.</strong> </p><br /><p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image024.jpg"></p><br /> <p align="left"><strong class='bbcode bold'>Click Connect</strong></p><br /> <p align="left"><img src="http://www.dimante.net/SonicwallPro200_Setup_files/image026.jpg"></p><br /> <p align="left"><strong class='bbcode bold'>A successful connection looks like this. </strong></p></div>]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Fri, 15 Feb 2008 13:23:02 -0600</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?15</guid>
</item>

<item>
<title>Thoughts?</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?12</link>
<description><![CDATA[For those of you that have UDR installed what are your initial thoughts on it?<br />]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Sat, 01 Dec 2007 11:00:10 -0600</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?12</guid>
</item>

<item>
<title>Welcome</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?11</link>
<description><![CDATA[Welcome to the forums.  If you have any suggestions or requests to make the forums better please let me know.  You need to sign up on the website to make posts or reply to posts.  I hope to see more and more people come and this forum become a reliable and informational location for the APECS / DISCOVERY.NET platform.<br /><br />-Gates-]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Tue, 27 Nov 2007 05:11:54 -0600</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?11</guid>
</item>

<item>
<title>Cisco 3000 / PIX NCP Client Configuration</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?10</link>
<description><![CDATA[NCP Secure Client and Cisco (3000series &amp; PIX)<br />ID:	10127<br />Operating Systems:	Keines / None,<br />Typ:	Information<br />NCP Secure Enterprise Client	8.10<br />NCP Secure Enterprise CE Client	2.0x<br />NCP Secure Entry Client	8.12<br /><br /><br />Some important things to be sure of before starting:<br /><br />1). the NCP Client (or derivative thereof, also referred to as NCP Client in this document) cannot co-exist with another VPN Client, so it is imperative that other VPN clients have been removed before proceeding. You will be able to use the NCP VPN Client to establish connections to many other VPN Gateways, and are by no means locked down to only using specific vendor's VPN gateways.<br /><br />In the case of the integrated VPN functionality of the PocketPC operating system, this is not to be activated, seeing as it cannot be removed.<br /><br />2). in this scenario, the NCP Client will emulate a Cisco Unity Client, so you do not need to enable special "Movian" options- some users had this enabled, thinking it would be necessary in order to let the NCP CE Client function seeing it too is a PDA VPN client. The NCP Client strictly uses IPsec standards and drafts; such as XAUTH, IKE-ConfigMode and NAT-T, and so there is no need to enable options specifically for the Movian, some of which are not even supported, such as Diffie-Hellman Group 7.<br /><br />3). The NCP client does NOT support the TCP encapsulation with a static/variable port number. The Cisco MUST BE configured to support NAT-T (IPSec over NAT-T). This requires configuration on the server side. This 'mode' works in parallel with existing configurations (does not influence existing connections) using TCP-encapsulation and is a standard defined by Cisco to replace the TCP encapsulation. The newer versions of the clients (v2.2x onwards) do support variable UDP (default:10000) encapsulation though. (see important note below)<br /><br />Cisco 3000: Configuration | System | Tunneling Protocols | IPSec | NAT Transparency<br />Enable the IPSec over NAT-T.<br />See for more information:<br />http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/4_0/config/tunnel.htm#1029463<br /><br />Cisco PIX: isakmp nat-traversal [natkeepalive]<br />See for more information:<br />http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/gl.htm#wp1027312<br /><br />IMPORTANT NOTE: It may occur that the connection is succesfully negotiated, but no traffic is passing through the tunnel; that is to say; the symbols all indicate that a connection has been established, but the Rx (receive) counter remains on 0. Upon inspecting the log, you will see that NAT-T is supported but has not been negotiated, because no NAT devices were detected between the concentrator and the client. However, the Cisco will still expect the packets to be encapsulated within UDP(default:10000), and therefore not respond. This is automatically negotiated with the v2.2x and newer clients; and will adapt to the UDP port set on the Cisco. If<br />however a connection is used where NAT devices are detected, the frames will be encapsulated within UDP4500, which then will work.<br /><br /><br />Configuration:<br />For some tips in how to configure a connection to the ISP using a PDA please refer to http://www.ncp.de/english/services/cekompat/<br /><br />IPSec General Settings:<br />you may want to define both the IKE and IPsec policies and lifetimes manually, but using Automatic Mode will normally work fine. If you do choose to manually define them; make sure these match the configuration as defined in the Cisco. Please note, the Automatic Mode will NOT negotiate proposals using DES, seeing as this is not considered secure. AES is a suitable replacement, as it is faster and more secure.<br />Exchange Mode: Depending on whether you are using pre-shared keys or certificates you want to select either:<br />Pre-shared keys (PSK): select Aggressive Mode or<br />X509 Certificates (RSA): select Main Mode.<br /><br />NOTE: Please also select the correct DH-Group for the PFS (Perfect Forward Secrecy).<br /><br />Identities:<br />When using Pre-shared keys: select Free string used to identify groups as (IKE-)Type and enter in the group name as the (IKE-)ID. Enable the use of Pre-shared keys, and enter in the group password there.<br /><br /> <img src='http://www.ncp.de/kbgrafiken/20.jpg' class='bbcode' alt=''  /> <br /><br />When using certificates: select ASN1 Distinguished name, as (IKE-)Type and then the information will be extracted from the certificate. Remember also to define which certificates are to be used (and in the case of PDAs, upload the certificates to the PDA)!<br /><br />Also enable the use of XAUTH, and enter in the XAUTH username and password.<br /><br />IP Address Assignment:<br />The NCP client supports Cisco's IKE-Config Mode, which you'll want to enable as well, this saves a lot of trouble configuring IP addresses that the client is going to use.<br /><br /><br />Disclaimer<br />Considerable care has been taken in the preparation of this document, errors in content, typographical or otherwise may occur. If you have any comments or recommendations concerning the accuracy, then please contact NCP as desired.<br />NCP makes no representations or warranties with respect to the contents or use of this document, and explicitly disclaims all expressed or implied warranties of merchantability or use for any particular purpose. Furthermore, NCP reserves the right to revise this publication and to make amendments to the content, at any time, without obligation to notify any person or entity of such revisions and changes.<br /><br />Trademarks<br />All trademarks or registered trademarks appearing in this manual belong to their respective owners.<br /><br />© 2005 NCP Engineering GmbH. All rights reserved.]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Sun, 25 Nov 2007 07:14:53 -0600</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?10</guid>
</item>

<item>
<title>NCP Support / Questions Forum</title>
<link>http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?7</link>
<description><![CDATA[<strong class='bbcode bold'><span style='font-size:14px'>Post any issues with NCP Secure VPN Client software here!  We can help you with setup, configuration, and general questions.</span></strong>]]></description>
<dc:creator>dimante</dc:creator>
<pubDate>Sun, 11 Nov 2007 06:09:38 -0600</pubDate>
<guid isPermaLink="true">http://mail.dimante.net/e107_plugins/forum/forum_viewtopic.php?7</guid>
</item>


				</channel>
				</rss>
