Unless otherwise expressly specified, the following known limitations of the NCP Secure Communications Software is valid for all supported operating systems.
Contents:
1. Configuring IPSec compression
2. Installation of the Gina DLL
3. User Logon and Logoff on Windows XP
4. The supplementary program NCP Client Tracer
5. Assignment of pool addresses
6. Automatic Media Detection
7. Troubles when working with AVM WLAN Stick
8. Update from a Network Drive
9. Wrong Registry Entries
10. Error in connection establishment with WLAN profile
11. No WLAN connection with EAP/TLS
12. Starting Error in "External Application"
13. Filter rules that do not permit automatic connection set-up
14. Firewall and automatic connection setup in the client configuration
15. Communication via application (Browser, Port 80) blocked by Firewall
The encryption types configured in the IPSec policy can only be individually compressed. To do this, a dummy line must be inserted under the encryption type that is to be compressed. After the dummy line has been inserted, set the protocol on "Comp" for this line. The IPSec compression displayed in this line then applies only for the encryption of the line above.
2. Installation of the Gina DLL under Windows XPIf the Gina DLL of another manufacturer is already loaded and started before the NCP Windows Logon, this Gina DLL must be disabled before the installation of the NCP Secure Client. Alternatively, the reference to the NCP Gina DLL must be manually changed in the registry of the other manufacturer. (NCPGINAx.DLL -> NCPGINA1.DLL)
Important Note:
If the Gina DLL, referred to in the registry does not exist, the system cannot be started (blue Screen)!
1. Logon and Change
Windows XP/Vista has the option to change users. In that case several users exist in the Windows start menu and all of them can be logged on.
2. Logoff and Logon with a New User
If a user logs off in the Windows start menu, while no other user is active at the same time, the user account is deleted and a prompt for a new user appears.
This user change (see 1.) is not supported by the NCP Secure Client.
Note:
To change a user simply logoff an then logon with another user (see 2.)
It is possible to save the log data from the supplemental program NCP Client Tracer in order to log a trace. The file name can be freely chosen and bears the extension LOG.
Please be aware that the Trace Program does NOT inform you when overwriting a previously existing LOG file!
Please make sure to choose new names for the LOG files when saving new traces!
5. Assignment of pool addressesIf the NCP Secure Server runs out of IP addresses from the pool, it can no longer assign IP addresses to incoming requests, consequently, it not will be possible to establish a connection. The requesting client will not be informed by a message, for security reasons, as to why his connection request was rejected. This is also why the NCP Secure Client doesn't display connection setup messages in the graphic status field.
6. Automatic Media DetectionIf a phonebook entry has been configured in the such a manner for "Automatic Media Detection" then it is strictly required that an (NAS) password be entered in the "Network dial-in" parameter field, otherwise the connection will not be setup.
7. Troubles when working with AVM WLAN StickUsing the Enterprise or Entry Client with an AVM WLAN Stick and WPA2 encryption under the Windows 64 bit operating systems XP or Vista the client monitor could freeze after establishing the connection (WLAN and VPN tunnel) with activated link firewall for several times. The operating system must be rebooted.
8. Update from a Network DriveIf the option "Active Firewall after Client has been terminated" (Firewall Settings / Options) is switched on, an update of the Secure Client can not be executed. First this option has to be deactivated before executing an update.
9. Wrong Registry EntriesBy executing an update or installating once more a Secure Client, wrong registry entries can cause errors. In this case a message box will be displayed which must be closed with "OK". As a result the errors will be removed. After that the system has to be rebooted and the installation or the update has to be started once more.
10. Error in connection establishment with WLAN profileIf the connection of a WLAN profile to an access point is tested by quickly pressing the buttons for connecting and separating then this may lead to an error in the connection establishment.
11. No WLAN connection with EAP/TLSAt the moment EAP/TLS is not supported for WiFi connections under Windows Vista and Windows 7.
12. Starting Error in "External Application"Select the feature "External Applications or Batch Files". The "Add" button allows you to select an application or batch file from your computer. The computer loads the application or batch-file according to the start options.
Additionally, the applications can also be bound to a certain profile. You can select this profile from the existing profile settings after you clicked the button "Add" or "Edit".
However, this feature fails and the external application is not started if the profile name contains commas. For this reason, please refrain from using commas in the name of the selected profile.
13. Filter rules that do not permit automatic connection set-upIf a rule is generated in the firewall that excludes automatic connection setup, then no data can flow over a connection from the client to the other side if the connection set-up type has been set to "Automatic" or "Alternating" in the client telephone book (profile settings), under the header "Connection control".
Remedy:
Either change the firewall rule so that automatic connection set-up is not excluded, or set "Manual" connection set-up in the client configuration.
If a rule is generated in the firewall that only permits data traffic over "familiar" networks and/or VPN networks, then automatic connection set-up cannot occur, even if it has been set in the client configuration (telephone book, profile settings) under the header "Connection control".
Remedy:
Either allow data traffic over "unfamiliar" networks in the firewall rule, or set the connection set-up to "Manual" in the client configuration.
Communication via an application (Browser, Port 80) may be blocked by the firewall if:
1. A virus scanner is active, working according to the principle of content security.
2. A firewall rule for an application has been configured for a browser via port 80.
Solution:
1. Deactivate virus scanner.
2. If only a single browser is used, the virus scanner may remain active provided its exe file is entered in the rule for the respective application. (This rule allows every browser to set up an internet connection.)