Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Kerberos over IPSEC VPN

Status
Not open for further replies.

andybosc

IS-IT--Management
Nov 16, 2003
4
AU
I have setup an Ipsec VPN tunnel between 2 sites. Users at the remote site have had major difficulties logging on to windows. The process would take about an hour. I have found out that Kerberos is the cause of the problem, trying to send a 2000 byte UDP packet over a VPN tunnel that will not fragment any packets. There is a way to set Kerberos to transmit over TCP with a smaller MTU value, but this involves a huge amount of work modifying registry values in alot of PCs. Is there any other alternative?

Thanx.
 
Sounds like you've already been there, but just in case this is covered in
Don't think you will find a way around this without modifying the registry by some means. The problem you are having in it's self may cause problems with the Group Policy approach that is suggested in this situation.

Another option would be to put the registry settings in a .reg file and running that on each machine.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top