Re: I have a few dumb questions



Tyler Cobb piffled away vaguely:

I'm learning about IPSec right now. I'm also learning that if I enable IPSec
on my DC and other machines in the domain, they can communicate just fine...
but if I disable IPSec on the DC and then on the other machines in the
domain, they cannot talk to each other anymore. I forced a policy refresh,
rebooted the computers, cleared the caches, everything I could think of. I'm
apparently missing a step even though I can visually verify that IPSec
policies are disabled on all machines in the domain. What am I doing wrong?

It's like the filters are still in place.

Thanks for any help you can give!

How about some more information? What version of server are you using?
What version of the OS on the client (including SP)? For instance, the
followin KB article describes an issue when a W2K or XPSP1 client modify
a policy on a W2K3 domain:

http://support.microsoft.com/kb/884909/en-us

What was your policy, desribe it? How did you remove it? Have you
tried the IPSec monitor tool to monitor what's happening? Any Event
Log entries look interesting? Have you tried searching the MS KB
yourself? Aren't you glad this is a lab you're working on and not a
production environment? You are using a lab, right? Right?

--

Catwalker
MCNGP #43
www.mcngp.com
"I have a gun. It's loaded. Shut up."

.



Relevant Pages

  • Re: Enable IPSEC on a Specific NIC only?
    ... with some subnet and drop all packets from others. ... If this needs to be done on many machines, ... IPsec policy cannot be done through group policy, ...
    (microsoft.public.security)
  • I have a few dumb questions
    ... I'm also learning that if I enable IPSec ... on my DC and other machines in the domain, ... but if I disable IPSec on the DC and then on the other machines in the ...
    (microsoft.public.cert.exam.mcsa)
  • Re: Configuring Port range in IPsec
    ... > policy. ... You can either use an IP address or subnet when creating a filter ... It's one of the serious weaknesses of the IPSec ... rules it can significantly impact the machines ...
    (microsoft.public.win2000.security)
  • Re: Should I install Certificate Authority to solve these problems ?
    ... You can use IPsec with or without certs from your PKI. ... negotiations to your AD machines or those trusting the ... > In the item 1 below, the tool in use is a HP server management tool (type ... >>> Management is pushing to get Certificate Authority ...
    (microsoft.public.win2000.security)
  • Re: IPSEC config
    ... spdadd 10.20.30.0/24 172.28.56.0/23 any -P out ipsec ... 15:24:18.927721 sunburn> acesfbsd: icmp: echo request ... fxp0: flags=8943mtu ... Then I have two machines on these nets that have routing pointing to ...
    (FreeBSD-Security)