今日有時間試下Win2k8+L2TP IPSec server...
兩個問題
1. 佢default又係rely-on MS-CHAP v2,即使佢可以EAP,但都只係EAP-MSCHAPv2,雖然話有IPSec PSK做encryption,但一日唔改第二隻authorization protocol,一日都係唔安全
2. Client機係NAT後面的話,Vista開始全部要改registry,DLLM M$!
http://support.microsoft.com/kb/926179
Android v4.1 + iOS 5.2都無事,係Win反而要改,M$你唔好去死