Click to Rate and Give Feedback
Tips
Memory is often the source of performance problems, and you should always rule out memory problems before examining other areas of the system. Here’s an overview of counters that you’ll want to track to uncover memory, caching, and virtual memory (paging) bottlenecks. ...

Read more!

You should run maintenance routines against databases on a daily basis. By default, Exchange Server runs maintenance tasks daily from 1:00 A.M. to 5:00 A.M. but you can customized the time if you so desire. ...

Read more!

You can manage SQL Server from a command line just as you would any other service. Here are the commands you need to know. ...

Read more!

Discover a new command line switch in Windows 7 for easily analyzing and troubleshooting power management settings. ...

Read more!

Windows 7 beta 1 includes new keyboard shortcuts that allow you to navigate and manage the Windows workspace more efficiently. Here are 10 shortcuts you should know. ...

Read more!

Related Articles

How do you allow network access to those who need it without sacrificing security? See how new technologies in Windows Server 2008, such as Windows Firewall with Advanced Security and Network Access Protection, let you implement a policy-based approach to help you achieve this goal. Ian Hameroff and Amith Krishnan 62 Configuring Roles with Server Manager A DNS server need not be a print server. One approach Windows Server 2008 takes to improve security and manageability is to simplify server roles so you can easily install only the tools and ...

Read more!

IEEE 802.1X authentication provides an additional security barrier for access to your intranet. See how Windows Vista and Windows Server 2008 make it a snap to implement IEEE 802.1X authentication for your wired network.

Joseph Davies

TechNet Magazine February 2008

...

Read more!

Getting ready to move to IPv6? The Cable Guy explains how you can use an IPv6 transition technology to get IPv6 connectivity and migrate to an IPv6-capable intranet.

Joseph Davies

TechNet Magazine March 2008

...

Read more!

NAP monitors the health of specified computers when they attempt to connect to a network and includes a number of mechanisms to enforce health requirements. This article gives readers an overview of these enforcement mechanisms and, as an example, takes a closer look at setting up DHCP enforcement

Greg Shields

TechNet Magazine May 2009

...

Read more!

Single Sign On offers many advantages for both end users and administrators. Here's a look at how Single Sign On can simplify implementation of wireless authentication for your network.

Joseph Davies

TechNet Magazine November 2007

...

Read more!

Also by this Author

The VPN protocols in Windows XP and Windows Server 2003 don’t work for some configurations. Get an in depth look at the various issues and see how Windows Server “Longhorn” and Windows Vista with Service Pack 1 will use the Secure Socket Tunneling Protocol to solve these problems.

Joseph Davies

TechNet Magazine June 2007

...

Read more!

Windows Server 2008 R2 and Windows 7 offer new features that support IPv6 for local and remote connectivity and for simplified management of host settings, as Joseph Davies explains.

Joseph Davies

TechNet Magazine July 2009

...

Read more!

The Internet Key Exchange protocol and Authenticated Internet Protocol are both used to determine keying material and negotiate security parameters for IPsec-protected communications. Get an in-depth look at how they work.

Joseph Davies

TechNet Magazine October 2007

...

Read more!

Single Sign On offers many advantages for both end users and administrators. Here's a look at how Single Sign On can simplify implementation of wireless authentication for your network.

Joseph Davies

TechNet Magazine November 2007

...

Read more!

Joseph Davies

TechNet Magazine February 2007

...

Read more!

Popular Articles

Raymond Chen looks at the skewed relationship bugs have to errors, and explains why it's important that programmers suffer as well as give results.

Raymond Chen

TechNet Magazine October 2008

...

Read more!

Aaron Margosis

TechNet Magazine August 2006

...

Read more!

Learn how you can implement error-handling in Windows PowerShell.

Don Jones

TechNet Magazine January 2009

...

Read more!

The upcoming release of Microsoft Identity Lifecycle Manager “2” offers many new features and enhancements. Explore the new portal experience and find out how you can cut costs with self-service tools, increase security compliance with business process modeling, and reduce development time with simplified development tools.

Aung Oo

TechNet Magazine January 2009

...

Read more!

Drivers fail, files get corrupted, disks crash--there are numerous uncontrollable reasons why Windows might fail. But all is not lost. Wes Miller explores the kinds of things that can go wrong in a Windows system, and explains how you can troubleshoot them to get your system working again.

Wes Miller

TechNet Magazine January 2009

...

Read more!

Our Blog

NAP monitors the health of specified computers when they attempt to connect to a network and includes a number of mechanisms to enforce health requirements. In this article, Geek of All Trades Greg Shields gives readers an overview of these enforcement mechanisms and, as an example, takes a closer look at setting ...

Read more!

Use Windows PowerShell to Manage Virtual Machines Here are a few examples of how you can use Windows PowerShell scripts to manage virtual machines running on a Server Core installation. Note that these scripts are presented as samples and may need to be customized to work in your environment.

Create a New ...

Read more!

Disabling an Unused Part of Group Policy Objects One way to disable a policy is to disable an unused part of the GPO. By disabling part of a policy that isn’t used, the application of GPOs and security will be faster.

Administer Windows Server 2008 Server Core from the Command Prompt ...

Read more!

In the August 2008 issue of TechNet Magazine, Paul Randal wrote an article Top Tips for Effective Database Maintenance.  It was geared toward "involuntary  DBAs" (IT pros who inadvertently wind up responsible for a SQL Server instance).  The article had a great response from our readers so Paul has written another ...

Read more!

Microsoft Forefront is designed to deliver an integrated security solution that makes it much easier to deploy and manage security across an organization’s IT infrastructure. In this, our annual security issue, we feature two articles that describe how Forefront Security protects instant messaging and e-mail.

Protect ...

Read more!

The Cable Guy IPv6 Traffic over VPN Connections
Joseph Davies


As you begin to evaluate the role of Internet Protocol version 6 (IPv6) on your intranet and start planning for its deployment, you should understand how IPv6 traffic is supported over virtual private network (VPN) connections in Windows. With VPN connections, you can extend your network to include links across public
networks such as the Internet. VPN connections are protected by strong authentication protocols to validate the credentials of the connecting user, and encryption methods to provide data confidentiality.
Windows® XP and Windows Server® 2003 include an IPv6 protocol stack, but many core services and networking components do not support IPv6. Windows Vista™ and Windows Server 2008 have full-featured support for IPv6, which is installed and enabled by default. In fact, almost all of the networking applications and services included with Windows Vista and Windows Server 2008 support IPv6. This month, I examine the support in Windows Vista, Windows Server 2008, Windows XP, and Windows Server 2003 for IPv6 traffic sent over VPN connections that are established across the Internet Protocol version 4 (IPv4) and IPv6 Internets.

VPN Connections across the IPv4 Internet
For most of today’s intranets, VPN connections are created across the IPv4 Internet. Figure 1 shows Windows-based components for VPN connections of this type. These components consist of the following:
Figure 1 Windows-based components for VPN connections across the IPv4 Internet (Click the image for a larger view)
VPN Client This is a computer that initiates a remote access VPN connection to a VPN server and communicates with intranet resources. A remote access VPN connection allows the VPN client to act as if it were directly connected to the intranet. A VPN client can run either client or server versions of Windows.
VPN Server This computer listens for remote VPN connection attempts, enforces authentication and connection requirements, and routes packets between VPN clients and intranet resources. A VPN server typically runs a server version of Windows with the Routing and Remote Access service.
VPN Router A VPN router is a computer that initiates or listens for site-to-site VPN connection attempts. A site-to-site VPN connection connects two portions of an intranet together. A VPN router runs a server version of Windows and the Routing and Remote Access service.
VPN Connection A VPN connection is the logical link between the VPN client and the VPN server or between VPN routers as defined by the encapsulation of a VPN protocol.
IPv6-Enabled Intranet This intranet can forward IPv6 traffic, either natively or tunneled as IPv4 packets.
IPv6/IPv4 Host This intranet node sends and receives IPv6 traffic, either natively or tunneled as IPv4 packets.
Windows-based VPN clients, servers, and routers can use the following VPN protocols to encapsulate the packets sent across the VPN connection: Point-to-Point Tunneling Protocol (PPTP), Layer Two Tunneling Protocol with Internet Protocol security (L2TP/IPsec), and Secure Socket Tunneling Protocol (SSTP). SSTP is only supported by Windows Vista with Service Pack 1 and Windows Server 2008.
For VPN connections across the IPv4 Internet, there are two methods that are used for sending IPv6: IPv6 packets tunneled as IPv4 packets, hereafter referred to as IPv6-over-IPv4 traffic, and native IPv6 traffic.
Throughout this column, support for IPv6 traffic across VPN connections is stated in terms of VPN protocols and versions of Windows. For remote access VPN connections, a given combination of VPN protocol and version of Windows implies support by both remote access client and remote access server components of Windows.

IPv6-over-IPv4 Traffic
In this method, a remote access client or an IPv6/IPv4 host on the intranet encapsulates IPv6 packets with an IPv4 header and sends the result as an IPv4 packet. For intranets, the IntraSite Automatic Tunnel Addressing Protocol (ISATAP) IPv6 transition technology (RFC 4214) allows IPv6/IPv4 nodes to exchange IPv6 traffic across an IPv4-only intranet. With ISATAP, you can enable IPv6 connectivity on your IPv4-only intranet without having to configure or upgrade your existing routers to support native IPv6 addressing and forwarding. For more information about ISATAP, see "IPv6 Transition Technologies" at microsoft.com/technet/network/ipv6/ipv6coexist.mspx.
Figure 2 shows the general packet structure for VPN traffic when sending an IPv4 packet using a VPN connection across the IPv4 Internet. The IPv4 packet is encapsulated by the VPN protocol with a header and, depending on the VPN protocol, a trailer. The result is encapsulated with an IPv4 header that allows forwarding across the IPv4 Internet.
Figure 2 IPv4 packets using a VPN connection across the IPv4 Internet 
For IPv6-over-IPv4 traffic, the payload of the IPv4 packet sent across the VPN connection is an IPv6 packet. Figure 3 shows the general packet structure for VPN traffic when sending an IPv6-over-IPv4 packet using a VPN connection across the IPv4 Internet.
Figure 3 IPv6-over-IPv4 packets using a VPN connection across the IPv4 Internet 
For remote access VPN connections, IPv6-over-IPv4 traffic across the IPv4 Internet is supported by PPTP and L2TP/IPsec in Windows Vista, Windows Server 2008, Windows XP SP1 or higher, and Windows Server 2003 and by SSTP in Windows Server 2008. For site-to-site VPN connections, IPv6-over-IPv4 traffic across the IPv4 Internet is supported by PPTP and L2TP/IPsec in Windows Server 2008 and Windows Server 2003.

Native IPv6 Traffic
For native IPv6 traffic, the VPN client, server, or router sends IPv6 packets across the VPN connection without the initial IPv4 encapsulation. This works for intranets that have native IPv6 connectivity and requires that the VPN clients, servers, and routers support the IPv6 Control Protocol (IPV6CP), RFC 2472, which defines how IPv6 nodes negotiate IPv6 configuration options for Point-to-Point Protocol (PPP)-based connections. Windows Vista and Windows Server 2008 support IPV6CP while Windows XP and Windows Server 2003 do not. Figure 4 shows the general packet structure for VPN traffic when sending a native IPv6 packet using a VPN connection across the IPv4 Internet.
Figure 4 Native IPv6 packets using a VPN connection across the IPv4 Internet 
For remote access VPN connections, native IPv6 traffic across the IPv4 Internet is supported by PPTP and L2TP/IPsec in Windows Vista and Windows Server 2008 and by SSTP in Windows Server 2008. For site-to-site VPN connections, native IPv6 traffic that travels across the IPv4 Internet is supported by PPTP and L2TP/IPsec in Windows Server 2008.

VPN Connections across the IPv6 Internet
You can also make VPN connections across the IPv6 Internet. Such VPN connections are uncommon now, but will become more prevalent as more Internet service providers offer IPv6 to their customers and more organizations include IPv6 Internet connectivity in their intranet edge networks.
In order to support VPN connections across the IPv6 Internet, the VPN protocols that are used must support connections over IPv6. In Windows Vista SP1 and Windows Server 2008, the L2TP/IPsec and SSTP VPN protocols support remote access VPN connections over IPv6. In Windows Server 2008, L2TP/IPsec supports site-to-site connections over IPv6. VPN connections across the IPv6 Internet use the same set of components as those for VPN connections across the IPv4 Internet for both remote access and site-to-site VPN connections.
There are also two ways of sending IPv6 packets over the IPv6 Internet: IPv6-over-IPv4 traffic and native IPv6 traffic. Figure 5 shows the general structure of IPv6-over-IPv4 packets when they are sent over a VPN connection across the IPv6 Internet.
Figure 5 IPv6-over-IPv4 packets using a VPN connection across the IPv6 Internet 
For remote access VPN connections, IPv6-over-IPv4 traffic across the IPv6 Internet is supported by L2TP/IPsec in Windows Vista and Windows Server 2008 and by SSTP in Windows Server 2008. For site-to-site VPN connections, IPv6-over- IPv4 traffic across the IPv6 Internet is supported by L2TP/IPsec in Windows Server 2008. Just as for IPv6-over-IPv4 traffic over the IPv4 Internet, IPv6-over-IPv4 traffic over the IPv6 Internet requires the deployment of an IPv6 transition technology such as ISATAP on your intranet.
Figure 6 shows the general structure of native IPv6 packets when they are sent over a VPN connection across the IPv6 Internet. Just as for native IPv6 traffic over the IPv4 Internet, native IPv6 traffic over the IPv6 Internet requires IPV6CP support and the deployment of native IPv6 connectivity on your intranet.
Figure 6 Native IPv6 packets using a VPN connection across the IPv6 Internet 
For remote access VPN connections, native IPv6 traffic across the IPv6 Internet is supported by L2TP/IPsec in Windows Vista and Windows Server 2008 and by SSTP in Windows Server 2008. For site-to-site VPN connections, native IPv6 traffic across the IPv6 Internet is supported by L2TP/IPsec in Windows Server 2008.

Wrapping Up
Figure 7 shows the four methods for sending IPv6 traffic over VPN connections and the support in Windows for the two different types of VPN connections. In a nutshell, if you are using an IPv6 transition technology such as ISATAP on your intranet, you can send IPv6-over-IPv4 traffic over VPN connections across both IPv4 and IPv6 Internets. If your intranet supports native IPv6 connectivity, you can send native IPv6 traffic over VPN connections across both the IPv4 and IPv6 Internets with Windows Vista and Windows Server 2008.

Method of Sending IPv6 Traffic Remote Access VPN Connections Site-to-Site VPN Connections
IPv6-over-IPv4 traffic over the IPv4 Internet PPTP and L2TP/IPsec in Windows Vista, Windows Server 2008, Windows XP SP1 or higher, and Windows Server 2003 SSTP in Windows Vista SP1 and Windows Server 2008 PPTP and L2TP/IPsec in Windows Server 2008 and Windows Server 2003
Native IPv6 traffic over the IPv4 Internet PPTP and L2TP/IPsec in Windows Vista and Windows Server 2008 SSTP in Windows Vista SP1 and Windows Server 2008 PPTP and L2TP/IPsec in Windows Server 2008
IPv6-over-IPv4 traffic over the IPv6 Internet L2TP/IPsec in Windows Vista and Windows Server 2008 SSTP in Windows Vista SP1 and Windows Server 2008 L2TP/IPsec in Windows Server 2008
Native IPv6 traffic over the IPv6 Internet L2TP/IPsec in Windows Vista and Windows Server 2008 SSTP in Windows Vista SP1 and Windows Server 2008 L2TP/IPsec in Windows Server 2008

Joseph Davies is a technical writer with Microsoft and has been teaching and writing about Windows networking topics since 1992. He has written eight books for Microsoft Press and is the author of the monthly online TechNet Cable Guy column.
© 2008 Microsoft Corporation and CMP Media, LLC. All rights reserved; reproduction in part or in whole without permission is prohibited.
Page view tracker