Solved

XAUTH With Windows XP?

Posted on 2003-10-31
2
1,897 Views
Last Modified: 2013-12-04
Hi there, here is my situation:

My corporate FW is a 3com superstack 3 firewall; it is also our VPN server and hosts all VPN connections to our network. Aside from its standard encryption and authentication, it offers XAUTH authentication. Our clients that are using Windows 2000 machines get a windows login prompt when they try to use the VPN from a remote location, but with the XP machines, we have to disable XAUTH, as no prompt appears and the connection cannot be validated.

When Xauth is off, then the XP machines connect fine. But with our setup we need to be able to offer this extra form of authentication.

Any ideas or opinions would be greatly appreciated.

Thank you,

Mike
0
Comment
Question by:UnifiedIT
2 Comments
 
LVL 11

Accepted Solution

by:
ewtaylor earned 200 total points
ID: 9659628
I do not think you caqn use xauth, can you setup radius or tacacs?
http://www.microsoft.com/windowsserver2003/techinfo/overview/vpnfaq.mspx
Q.  Why doesn't Microsoft implement IPSec tunnel mode with XAUTH and mode config?
   
A.  There are several key reasons for this.

XAUTH contains serious security flaws for which no known fix is available and has been rejected for IETF standardization. Given this, Microsoft believes that it would be irresponsible for us to endorse this technology, especially when IETF standards-based technology is under development.
XAUTH is incompatible with existing IETF authentication frameworks such as EAP and GSS-API. This means that developers who want to develop authentication techniques for the Windows platform would need to develop their methods using multiple, incompatible APIs. This prevents customers from using existing authentication methods within remote access scenarios. For developers, it increases the complexity and cost of developing a new authentication method. Rather than introducing another authentication framework to the detriment of customers and developers, Microsoft endorses efforts within IETF and IEEE to extend the applicability of EAP. This allows customers and developers to leverage their efforts, developing authentication methods with universal applicability, such as in wireless scenarios (via 802.1X).
Because of the poor interoperability of XAUTH and mode config, Microsoft could not implement the technology and have it work with more than one vendor.
L2TP/IPSec is already an interoperable standard that is supported in commercial products from leading networking companies and can be implemented in models similar to XAUTH with IPSec but with much stronger security, reliable accounting, and standards-based configuration.
The IETF rejected XAUTH and mode config and has a more appropriate IPSec tunnel mode-based remote access solution in development through the IPSRA working group.
 
0
 
LVL 2

Author Comment

by:UnifiedIT
ID: 9659643
Thanks.. It looks like I missed that link when searching the Net. Thank you for the find.

Mike
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, a new law in my state forced us to get a top-to-bottom analysis of all of our contract client's networks. While we have documentation, it was spotty at best for some - and in any event it needed to be checked against reality. That was m…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question