SSL/TLS provides transport-level security with key negotiation,
encryption and traffic integrity checking. The use of SSL/TLS over
TCP port 443 (by default; port can be changed) allows SSTP to pass through virtually all
firewalls and
proxy servers except for authenticated web proxies. and available on
Windows Vista SP1 and later, in
RouterOS since version 5.0, and in
SEIL since its firmware version 3.50. It is fully integrated with the RRAS architecture in these operating systems, allowing its use with
Winlogon or
smart-card authentication, remote-access policies and the Windows VPN client. SSTP suffers from the same performance limitations as any other IP-over-TCP tunnel. In general, performance will be acceptable only as long as there is sufficient excess bandwidth on the un-tunneled network link to guarantee that the tunneled TCP timers do not expire. If this becomes untrue, performance falls off dramatically due to the
TCP meltdown problem. SSTP supports user authentication only; it does not support device authentication or computer authentication. == Packet structure ==