Article ID: 929856 - Last Review: March 17, 2007 - Revision: 1.5 You receive a "741" or a "742" error message when you try to establish a VPN connection by using L2TP/IPsec from a Windows client computer to a VPN serverOn This PageSYMPTOMSYou experience one of the following symptoms when you try to establish a virtual private network (VPN) connection by using "Layer Two Tunneling Protocol with IPsec" (L2TP/IPsec) from a Windows client computer to a VPN server.
CAUSEThis issue occurs if the encryption level that the Windows client computer uses does not match the encryption level that the VPN server uses. For example, this issue occurs if the client computer uses 40-bit or 56-bit RC4 encryption, and the VPN server only supports a 128-bit RC4-based encryption algorithm.
Or, this issue occurs if the client computer uses 128-bit RC4 encryption and the server only supports a 40-bit or a 56-bit RC4-based encryption algorithm.
WORKAROUNDTo work around this issue, use one of the following procedures, as appropriate for your situation. The Windows client computer is running Windows XP, Windows Server 2003, or Windows 2000, and you connect to a VPN server that is running Windows Server 2008 or Windows VistaUse one of the following methods.Note Method 1 is the recommended method to use in this scenario. Method 1: Change the encryption setting on the VPN client computerChange the encryption setting in the VPN connection on the client computer to use maximum strength encryption. After you do this, Triple Data Encryption Standard (3DES) encryption is used to establish the VPN connection. To change the encryption setting in the VPN connection on the client computer, follow these steps:
Method 2: Change the encryption setting on the VPN serverImportant This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows Add the AllowL2TPWeakCrypto registry entry to the VPN server to change the encryption setting that the Routing and Remote Access service uses. After you do this, the "Message Digest 5" (MD5) algorithm or Data Encryption Standard (DES) encryption is enabled on the VPN server. To change the encryption setting on the VPN server, follow these steps:
The Windows client computer is running Windows Server 2008 or Windows Vista, and you connect to a VPN server that is running Windows XP, Windows Server 2003, or Windows 2000Use one of the following methods.Note Method 1 is the recommended method to use in this scenario. Method 1: Change the encryption setting on the VPN serverChange the encryption setting in the routing and remote access policy on the VPN server to maximum strength encryption. After you do this, Triple Data Encryption Standard (3DES) encryption is used to establish the VPN connection.Method 2: Change the encryption setting on the VPN client computerImportant This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows Add the AllowL2TPWeakCrypto registry entry to change the encryption setting that the Routing and Remote Access service uses on the client computer. After you do this, MD5 encryption or DES encryption is enabled on the client computer. To change the encryption setting, follow these steps:
APPLIES TO
| Article Translations
|
Back to the top
