Overview
The VPN
provides a solution to work through the various port blocks
and other things that Internet Service Providers (ISPs) do to
protect their clients and try to prevent spam, virus outbreaks,
and other network abuse. These preventative measures often interrupt
or prevent legitimate work from happening. The MIT VPN can help
resolve a number of problems associated with e-mail, Windows
file sharing, and other network-based applications without needing
to determine the particular preventative measures your ISP has
implemented.
MIT is using the Cisco VPN client with a customized configuration. Currently, IS&T offers VPN client 4.8.02 which is fully compatible with Windows 2000 and XP. It also works with Windows Vista, but warns of incompatibility.
The main foci of this release effort is to provide MIT community with a customized version of VPN clent 5.0 fully compatible with Windows Vista, XP and 2000.
Timeline
August 2007
News
There are no news items at this time.
Announcements
There are no announcements at this time
[Back to top]
Key Decisions
- We will create and release a customized installer to include
the MIT profile in an effort to make the installation process
for the end user easy and straight forward.
Notable Features
- Provides full support for 32-bit Windows Vista
- Solves various e-mail, file sharing and other network problems for clients connecting from off campus
- Utilizes kerberos principle for authentication, so no separate VPN password needed
[Back to top]
System
Requirements
- Windows 2000, XP and Vista - 32bit only
Testing
A draft test plan is in the works.
[Back
to top]
Known
Issues
Advisory: Windows Vista does NOT support the following:
- Upgrades from Windows XP to Vista.
- Start Before Logon
- SmartCard Authentication
- Integrated Firewall
- InstallShield
- 64bit support
- AutoUpdate
- Online Help - Provided only in English
Known Issues:
CSCsi25954 unity vista: certificate authentication via smartcards are not supported
CSCsi25985 unity vista: user not prompted to reconnect after sleep or hibernation
CSCsi26001 unity xp-vista: reauth on rekey with saved password causes disconnect
CSCsi26020 unity vista: firewall tab under stats still shows
CSCsi26050 unity vista: installshield packge does not work on vista
CSCsi26069 unity vista: error 1721 when installing client on vista 64bit
CSCsi26086 unity vista: upgrading from xp to vista not supported
CSCsi26106 unity vista: reason 442: failed to enable virtual adapter
CSCsi26159 unity vista: bsod during install/uninstall/sleep with active ras
CSCsi26229 unity vista: integrated firewall not installed on vista
CSCsi35107 unity vista: start before login “sbl” not functioning
Resolved Issues:
CSCsh52300 XSS vulnerability via search facility in online help
CSCsg36636 unity-vista: default tunnel route removed due to dhcp renewal.
CSCsh24112 No sound plays through PC sound card when vpn client connected
CSCsg57280 unity: unable to set mtu via tool when uac is enabled.
CSCsh45583 VPN Client with AES encryption causes Windows Media Player Failure
CSCsh02040 unity-vista: installer does not detect usb adapter.
CSCsd09675 Vista: unable to enable logging subsystem when firewall is enabled
CSCsh36040 unity-vista: set flag in inf for va to disable network location prompts.
CSCse39772 Vista: unable to install client under uac in vista 5384.
CSCsh02054 unity-vista-de: importing pcf causes data redir resulting in corrupt pcf
CSCsh02887 unity-vista: stateful firewall does not start. *** Feature removed until ZoneLabs releases Vista compatible product.
CSCsc74781 feature unity windows custom localizations
CSCsf03420 unity client produces one way traffic with skype and aes encryption
CSCsh12290 unity windows install fails to install profiles on msi only
CSCse77792 unity windows aes encrypt crashes .net hash table application
CSCeh97583 unity windows cli commands to send pwd auth only once
CSCsi26033 unity vista: log information not shown in interface log window
Workarounds for Vista:
Error 412: The remote peer is no longer responding Upgrade local NAT device's firmware If this is not possible, switch to TCP If this is not possible, use the following keyword in connection profile (*.pcf):UseLegacyIKEPort=1 CAVEAT: If you are using Domain Isolation customer will not be able to use the UseLegacyIKEPort keyword as this conflicts with Microsoft's domain isolation.
Error 442: Failed to enable virtual adapter Open Network and Sharing Center Open Network Connection Manager Enable the virtual adapter (“Cisco VPN Adapter”) Right-click on it and select “Diagnose” Select “Fix…” If this doesn't work Run the following from ‘cmd': reg add HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v ArpRetryCount /t REG_DWORD /d 0 /f Reboot NOTE: If customer has UAC enabled, s/he must run ‘cmd' as administrator.
Error 1721 (At install time.) Client does not support 64bit.
[Back
to top]
Documentation
Existing or Planned Documentation:
| Documentation Name |
Exists |
Draft Ready |
Ready |
Assigned To |
| VPN Service Front Door |
No |
No |
No |
TBD |
|
VPN Product Front Door - Windows |
No |
No |
No |
TBD |
|
VPN Known Issues/Stock Answers |
No |
No |
No |
TBD |
Release Team
 |
Alexander Kozlov- SWRT |
| |
Product Release Coordinator |
 |
Deb Bowser - SWRT |
| |
Quality Assurance Coordinator |
 |
|
| |
|
 |
|
| |
|
 |
|
| |
|
If you would like to contact the team, please send email to vpn-release@mit.edu.
Meeting Minutes
- No Meeting Minutes at this time.
Support
If you have a question or need assistance,
please contact the Computing Help Desk
at computing-help@mit.edu
or x3-1101 or visit their
web site for more support resources.