Re: I have a few dumb questions



Tyler Cobb piffled away vaguely:

I'm learning about IPSec right now. I'm also learning that if I enable IPSec
on my DC and other machines in the domain, they can communicate just fine...
but if I disable IPSec on the DC and then on the other machines in the
domain, they cannot talk to each other anymore. I forced a policy refresh,
rebooted the computers, cleared the caches, everything I could think of. I'm
apparently missing a step even though I can visually verify that IPSec
policies are disabled on all machines in the domain. What am I doing wrong?

It's like the filters are still in place.

Thanks for any help you can give!

Here's another general article on troubleshooting IPSec in W2K:

http://support.microsoft.com/kb/257225/en-us

Much of it can be used to troubleshoot W2K3 as well.
--

Catwalker
MCNGP #43
www.mcngp.com
"I have a gun. It's loaded. Shut up."

.



Relevant Pages

  • Re: I have a few dumb questions
    ... on my DC and other machines in the domain, ... but if I disable IPSec on the DC and then on the other machines in the ... I forced a policy refresh, ... apparently missing a step even though I can visually verify that IPSec ...
    (microsoft.public.cert.exam.mcsa)
  • Re: em problems on supermicro 5015M-MT+
    ... We have 3 supermicro 5015M-MT+ machines that are identical hw ... When one of the 64 bit systems tries to communicate with the 32 bit box or any ... 320KB/s when interface is in 100baseTX full-duplex ... If nobody can come up with any good ideas we will probably try installing 32 ...
    (freebsd-net)
  • em problems on supermicro 5015M-MT+
    ... We have 3 supermicro 5015M-MT+ machines that are identical hw ... When one of the 64 bit systems tries to communicate with the 32 bit box or any ... 320KB/s when interface is in 100baseTX full-duplex ... If nobody can come up with any good ideas we will probably try installing 32 ...
    (freebsd-net)
  • Re: custom subnet mask
    ... A 2.x can communitcate with 3.x without the router though. ... If these machines use the network heavily you may have ... >>so with your 255.255.254.0 mask the groups you can use are: ... >>> A PC with a 192.168.1.x IP could communicate with both a PC with a ...
    (microsoft.public.win2000.networking)
  • Re: Firewall Suggestions
    ... likely run into the same thing with most of the personal firewalls. ... conflicting stuff on the machines and you have more problems. ... > When we first set up ZAP we had to put all the IP addresses for each ... > computer in the Trusted Zone to even get them to communicate at all. ...
    (comp.security.firewalls)