Description

Logging into Windows 2000 domain using built in Windows 2000 IPSec client

Symptoms

Environment:
  • Windows 2000 internal IPSec client
  • No NetScreen Remote client involved
  • Windows 2000 domain
  • Active Directory
  • Using Kerberos for domain authentication
Symptoms & Errors:
  • VPN is working
  • Cannot log into Windows 2000 domain

Solution

 
When building an IPSec tunnel using Windows 2000 built in IPSec client, Kerberos is not being sent through the VPN.  Microsoft sends this information in the clear, and not through the IPSec tunnel.  The workaround is to build a VPN as you normally would, but include a clear text policy to allow Kerberos traffic coming inbound to the PDC on the internal network.
 
Here are the steps on configuration from the NetScreen side:
  1. Build a VPN like you normally would
  2. Define a custom service for Kerberos, and define this with TCP destination port 88, and UDP destination port 88.
  3. Create a MIP which maps to the PDC on the internal network
  4. Create an incoming policy, with the source as the PC, destination as the MIP, and using the custom defined service Kerberos.

For more information on building the VPN from Windows 2000 client to NetScreen, please click here


Former Article Id

nskb1002