What do you mean by VPN client software ? On the PIX or on Vista ?
Main Topics
Browse All TopicsUsing a Windows Vista Enterprise edition (32bit) on labtop.
We have a VPN setup for our office network using Windows 2003 Ent. servers behind a Cisco PIX firewall. The PIX firewall handles the VPN connection from remote users.
On Windows XP the connection works when remotely connecting to the VPN.
Type of VPN : 'Automatic'
Requires data encryption with user/password
TCP/IP , Client for Microsoft Networks used
The same connection setup on Vista OS does not work. It connects to the server, but during the process of authenticating username & password, it fails. It does not give any specific reason for failure of connection.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Doc- I am guessing you are not using the Cisco client..
for the cisco client you would click on a padlock icon to connect to the VPN...
if that is NOT what you are using, then you are using PPTP VPN.
For Vista to work with that and PIX, you must enable the CHAP options:
Rightclick the VPN connection
Choose Properties
Security Tab,
Advanced (Custom)
Settings
make sure Challenge Handshake Authentication Protocol is enabled.
Click OK several times.
Attempt your connection.
Good luck.
Tried the CHAP option but didn't work. Still fails during the verifying username & password stage.
Interesting to note that when CHAP was enabled, it showed a warning message that if PAP and/or CHAP are enabled together, if either one is negotiated, there will not be any encryption.
This would defeat the whole point of a secure VPN connection.
I even tried the 'Option encryption (connect even if no encryption)' without any luck !
Protocols enabled by default for this connection:
TCP/IPv6
TCP/IPv4
File & Printer Sharing for MS networks
QoS Packet Scheduler
Client for MS Networks
Type of VPN: 'Automatic'
IPSEC settings: 'Use Certiticate for authentication - Verify the Name & Usage attributes of the server's certificate.'
-------------
If it doesn't work on a regular Vista VPN connection, then is the PIX client application the only choice ?
Is it for download or was it shipped along with the PIX firewall ?
Doc...
Keep playing with settings. it should work.
For the PIX and Windows to PPTP with each other, you have to really enable all those old protocols. Try enabling everything on the corresponding property page... all the chaps, ms-chaps, older chaps etc.
As far as encryption, I seem to remember it is really just the initial handshake that is not encrypted... the resulting VPN tunnel is.... But: 1- I can';t back that up & 2- unencrypted anything is not good with a VPN.
Even if you get it working, I would suggest looking into using the CIsco VPN Client...
like all the guys posted above... they of course thought you running that, because why not....it is solid, fast... it just works real nice. Basically, ditch the PPTP if you can... but you will have to redo your PIX side of things... in fact, with the cisco client you can authenticate against the active directory with IAS in win2k3... one less userdb to deal with!
sorry bout that last bit, sometimes i get excited;)
Yes, you will need a cisco login to download the client.
And, make sure you get a Vista compatible version like mentioned before.
Ok. Played around with it a bit and it works.
Enabled 'Unencrypted Password (PAP)' in the security settings along with the CHAP & MS-CHAP-v2.
As well, I had to pick 'Optional Encryption'.
Now it works ! Thanks.
But obviously the security settings are much lower than expected on a VPN connection. So the viable option is to try for the PIX VPN client.
Just a quick question; How do you get a CISCO login ? Does the PIX firewall hardware need to be registered or.... ?
Thanks.
best way to get a login is with a SmartNet contract... you can go through CDW or similar.
you will need to associate the contract with a serial number... and that should be your pix.
at that point you will also have access to newer pix OS!
just thought...you may have trouble, i don't know if they will offer contracts for older equipment... but, if you got a support contract for something else you would still have access to the vpn client...
but i don't think you are 'supposed' to download that.
glad to help out! thanks
Business Accounts
Answer for Membership
by: grbladesPosted on 2007-10-25 at 13:35:06ID: 20151194
What version of the software VPN client are you running?
You need at least version 5 for vista support.