The Cisco client is not for IPSec, it works with Cisco's own standard of VPN


Sorry - *bzzzt*.  Cisco's VPN (Concentrator or ASA-based) is IPSec, it just has a funky authentication layer and does NAT-T over port 4500.  It does the standard IKE over UDP-500 (XAUTH group, mutual group, or cert), then inserts a user-authentication shim (RADIUS, TACACS, etc.), then negotiates the IPSec tunnel, usually 3DES-128.  IPSec has always been a bit fuzzy (intentionally, I think) about how the keying & auth is set up - that's why so few IPSec implementations work well together without low-level twiddling.

RB

Reply via email to