For some reason you started a new threat, so let's continue here....
What client do you have on your Pocket PC?
How is it configured? The same as your Win2K system?
Is it using Agressive Mode? Does ASL support that?
What authentication method is it using? XAUTH? X.509?
What Identity? 822name? FQDN? DN?
Dynamically addressed IPsec clients are poorly supported in the RFCs, In my NOT so humble opinion, as I let it happen [:(]
And sitting 30 feet from my is Paul Lambert, the first IPsec chair that set it up much this way. Actually the problem is IKE, not IPsec....
Anyway, tell us a bit about the config options. Did you match them up to your gateway?
Oh, and some clients require you to start them. Others only start when a packet attempts to go out the VPN interface.
This thread was automatically locked due to age.