Hello, I work for a very large corp. that has a huge amount of ras users and a load of users going to vpn as they get highspeed. Our users are all over the world, I support most of them from the helpdesk level, but have found myself doing the second level and third level support for them as well since no one really seems to know what is going on. (Thats what happens when 4 or 5 different teams have been working on the different parts of the whole and not as a team) Thats ok though I just received employee of the month for the entire company of 20000+ for the work I have been doing.
Anyway, We are using Nortel for the client and Rsa SecurID for the authentication. Nortel uses IPSec (and not pptp) and is not friendy with ISP's that block IPSec or use NAT -Though a new client just came out and has tested very well in using NAT. Here are issues that we have ran into.
1. DHCP Lease - while connected using IPSec your pc will not allow your ISP to renew the ip address, therefor you will be disconnected from your ISP and then vpn will drop and your isp will come back on so fast that it only appears that vpn has dropped. You can verify this by doing a ipconfig /all at teh command prompt and look at your lease, you will be kicked off at 87.5% of it. The new Client 4.5 will allow the isp to renew if it is the same address and will not be an issue no longer. Or if you use a router, the router will give your pc a lease of 24 hours by norm and the isp will not have anything to do with it.
2. domain login, you do not want your pc to try and connect to a domain before connecting with vpn (win 9x,me), either cancel past the first domain login, or select windows login instead of client for microsoft networks in the network configuration window. For windows 2000 and xp, you must have the correct cached credentials, this means either by connecting straight into the network via lan at least once, or login using dialup , after you cache then you can reset your passords just fine over vpn and it will cache correctly.
3. network resources, you must have your pc added to the domain to get full access to the network. If the pc is not connected (varies depending on the network) here you would only be able to view intranet pages and get to outlook, mapped drives and printers are unavailable. There are work arounds, but you must know your network pretty well to know what to change. But more or less the easiest way to not run into problems is just make sure your pc is added.
I have tons to write about and just wanted to touch base on a few things I will go more into detail over the time any specific questions feel free to ask.