A Windows Vista-based or Windows Server 2008-based computer behind a NAT device cannot communicate with another computer through an IPsec tunnel-mode connection
You use a Windows Vista-based or Windows Server 2008-based
computer that is behind a Network Address Translation (NAT)
device. When you use this computer to try to communicate with another computer through an Internet
Protocol security (IPsec) tunnel-mode connection, the connection fails.
This issue may occur if more than one computer shares the same source port. Windows Vista and Windows Server 2008 do not support
tunnel-mode connections
when the computer is behind an NAT device. Therefore, a conflict may occur.
A hotfix is available to resolve this issue. This hotfix
adds the support for IPsec
when the computer is behind a NAT device.
Hotfix information
A
supported hotfix is available from Microsoft. However, this hotfix is intended
to correct only the problem that is described in this article. Apply this
hotfix only to systems that are experiencing this specific problem. This hotfix
might receive additional testing. Therefore, if you are not severely affected
by this problem, we recommend that you wait for the next software update that
contains this hotfix.
If the hotfix is available for download, there
is a "Hotfix download available" section at the top of this Knowledge Base
article. If this section does not appear, contact Microsoft Customer Service
and Support to obtain the hotfix.
Note If additional issues occur or if any troubleshooting is required,
you might have to create a separate service request. The usual support costs
will apply to additional support questions and issues that do not qualify for
this specific hotfix. For a complete list of Microsoft Customer Service and
Support telephone numbers or to create a separate service request, visit the
following Microsoft Web site:
Note The "Hotfix download available" form displays the languages for
which the hotfix is available. If you do not see your language, it is because a
hotfix is not available for that language.
Important Windows Vista and Windows Server 2008 hotfixes are included in the same packages. However, only one of these products may be listed on the “Hotfix Request” page. To request the hotfix package that applies to both Windows Vista and Windows Server 2008, just select the product that is listed on the page.
Prerequisites
To apply this hotfix, the computer must run one of the following:
Windows Vista Service Pack 1
Windows Server 2008
Restart requirement
You have to restart the computer after you apply this hotfix.
Hotfix replacement information
This hotfix does not replace any other previously released
hotfixes.
The English
version of this hotfix has the file attributes (or later file attributes) that
are listed in the following table. The dates and times for these files are
listed in Coordinated Universal Time (UTC). When you view the file information,
it is converted to local time. To find the difference between UTC and local
time, use the Time Zone tab in the Date and
Time item in Control Panel.
Windows Vista and Windows Server 2008 file information note
The MANIFEST files (.manifest) and MUM files (.mum) installed
for each environment are listed
separately . MUM and MANIFEST files, and the associated security
catalog (.cat) files, are very important to maintaining the state of the updated
component. The security catalog files (attributes not listed) are signed with a
Microsoft digital signature.
For all supported x86-based versions of Windows Vista and Windows Server 2008
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
Netio.sys
6.0.6001.22260
223,288
09-Sep-2008
05:42
x86
Bfe.dll
6.0.6001.22260
328,704
09-Sep-2008
05:27
x86
Fwpkclnt.sys
6.0.6001.22260
101,432
09-Sep-2008
05:34
x86
Fwpuclnt.dll
6.0.6001.22260
595,456
09-Sep-2008
05:27
x86
Ikeext.dll
6.0.6001.22260
438,272
09-Sep-2008
05:27
x86
Wfp.mof
Not
Applicable
814
18-Dec-2007
21:11
Not
Applicable
Wfp.tmf
Not
Applicable
175,508
09-Sep-2008
03:28
Not
Applicable
Tcpip.sys
6.0.6001.22260
891,960
09-Sep-2008
05:43
x86
For all supported x64-based versions of Windows Vista and Windows Server 2008
Collapse this tableExpand this table
File name
File version
File
size
Date
Time
Platform
Netio.sys
6.0.6001.22260
345,656
09-Sep-2008
04:51
x64
Bfe.dll
6.0.6001.22260
458,240
09-Sep-2008
04:46
x64
Fwpkclnt.sys
6.0.6001.22260
168,504
09-Sep-2008
04:51
x64
Fwpuclnt.dll
6.0.6001.22260
779,776
09-Sep-2008
04:47
x64
Ikeext.dll
6.0.6001.22260
454,656
09-Sep-2008
04:47
x64
Wfp.mof
Not
Applicable
814
18-Dec-2007
21:10
Not
Applicable
Wfp.tmf
Not
Applicable
174,680
09-Sep-2008
02:44
Not
Applicable
Tcpip.sys
6.0.6001.22260
1,419,320
09-Sep-2008
04:53
x64
Fwpuclnt.dll
6.0.6001.22260
595,456
09-Sep-2008
05:27
x86
Wfp.mof
Not
Applicable
814
18-Dec-2007
21:11
Not
Applicable
For all supported Itanium-based versions of Windows Server 2008