Solved

XAUTH With Windows XP?

Posted on 2003-10-31
2
1,900 Views
Last Modified: 2013-12-04
Hi there, here is my situation:

My corporate FW is a 3com superstack 3 firewall; it is also our VPN server and hosts all VPN connections to our network. Aside from its standard encryption and authentication, it offers XAUTH authentication. Our clients that are using Windows 2000 machines get a windows login prompt when they try to use the VPN from a remote location, but with the XP machines, we have to disable XAUTH, as no prompt appears and the connection cannot be validated.

When Xauth is off, then the XP machines connect fine. But with our setup we need to be able to offer this extra form of authentication.

Any ideas or opinions would be greatly appreciated.

Thank you,

Mike
0
Comment
Question by:UnifiedIT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 11

Accepted Solution

by:
ewtaylor earned 200 total points
ID: 9659628
I do not think you caqn use xauth, can you setup radius or tacacs?
http://www.microsoft.com/windowsserver2003/techinfo/overview/vpnfaq.mspx
Q.  Why doesn't Microsoft implement IPSec tunnel mode with XAUTH and mode config?
   
A.  There are several key reasons for this.

XAUTH contains serious security flaws for which no known fix is available and has been rejected for IETF standardization. Given this, Microsoft believes that it would be irresponsible for us to endorse this technology, especially when IETF standards-based technology is under development.
XAUTH is incompatible with existing IETF authentication frameworks such as EAP and GSS-API. This means that developers who want to develop authentication techniques for the Windows platform would need to develop their methods using multiple, incompatible APIs. This prevents customers from using existing authentication methods within remote access scenarios. For developers, it increases the complexity and cost of developing a new authentication method. Rather than introducing another authentication framework to the detriment of customers and developers, Microsoft endorses efforts within IETF and IEEE to extend the applicability of EAP. This allows customers and developers to leverage their efforts, developing authentication methods with universal applicability, such as in wireless scenarios (via 802.1X).
Because of the poor interoperability of XAUTH and mode config, Microsoft could not implement the technology and have it work with more than one vendor.
L2TP/IPSec is already an interoperable standard that is supported in commercial products from leading networking companies and can be implemented in models similar to XAUTH with IPSec but with much stronger security, reliable accounting, and standards-based configuration.
The IETF rejected XAUTH and mode config and has a more appropriate IPSec tunnel mode-based remote access solution in development through the IPSRA working group.
 
0
 
LVL 2

Author Comment

by:UnifiedIT
ID: 9659643
Thanks.. It looks like I missed that link when searching the Net. Thank you for the find.

Mike
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question