You are on page 1of 1

VPN PROTOCOLS

VPN Protocol Authentication Security Notes


PPTP (Point-to-Point MS-CHAP,MS- Confidentiality (MPPE) Least secure, most
Tunneling Protocol) CHAPv2,EAP,PEAP common and
compatible. Easy to
configure.
L2TP/IPSec (Layer 2 Certificate based IPSec IPSec integrity, Computer certs
Tunneling Protocol) for authentication encryption, required, IPv4 an IPv6
confidentiality
SSTP (Secure Socket SSL SSL integrity, More compatible with
Tunneling Protocol) encryption, firewalls, NAT, proxy.
confidentiality Windows server 2008,
Vista, Win7. Client must
trust cert on RRAS Sever
IKEv2 EAP, Certificate-based, Confidentiality, origin Win7 only. Supports
PEAP, MS-CHAPv2, EAP- authentication, replay VPN reconnect.
MSCHAPv2 protection, integrity

AUTHENTICATION PROTOCOLS
Authentication Protocol Notes
PAP (Password Authentication Protocol) Not secure. Not enabled for win 7 and windows
server 2008. Can enable for third-party VPNs.
CHAP (Challenge Handshake Authentication Password-based. Not supported by windows
Protocol) server 2008 VPN.
MS-CHAPv2 (Microsoft Challenge Handshake Password-based. Can use currently logged-on user.
Authentication Protocol version 2)
PEAP/PEAP-TLS (Protected Extensible Certificate-based authentication for users. VPN
Authentication Protocol with Transport Layer server has a computer certificate.
Security )
Smart Card or other certificate Certificate-based authentication for users.
Certificate can be smart card or users computer.

You might also like