IPSec IKE Phase II Malfunction

From: Jason Vorbeck (jason_at_actsoft.com)
Date: 01/28/05


Date: Fri, 28 Jan 2005 12:18:42 -0500

I think I may have found a bug in the ISA 2004 site to site IPSec
configuration interface. If you build an IPSec tunnel, and in the IPSec
config Phase II screen you specify to generate a new key (key expiration by
time) by time it does not matter what time you specify the system builds the
tunnel with 1024000 seconds. This can cause a big headache in trying to
determine why you cant successfully establish a tunnel to whatever remote
gateway you are trying to do it with, because in my case the Symantec
Velociraptor does correctly use the specified time expiration interval you
set. The tunnel with not successfully establish unless the IPSec parameters
match on both ends. Fortunately if you turn off the time based rekeying then
it does set the value at 0 so I was able to get the tunnel to establish by
turning off the expiration on both ends. You can see the value inserted into
the tunnel configuration by the interface by right clicking the tunnel and
choosing IPSec policy summary from the dropdown menu. Has anyone seen this
behavior in their tunnel config?? Can anyone reproduce this? Microsoft? I
would like to know if it is truly an error so I can watch for a patch
because I would like to rekey the tunnel based on time over volume.

Thank you,
Jason Vorbeck



Relevant Pages

  • ipsec config problem :URGENT HELP NEEDED
    ... Subject: ipsec config problem:URGENT HELP NEEDED ... I need some help for this ipsec tunnel configuration that i am trying to ... I have configured ipsec by using the command 'ipsec' at the command prompt and ... also the configuration needs a tunnel src address and tunnel dest address. ...
    (Focus-SUN)
  • RE: ipsec config problem :URGENT HELP NEEDED
    ... Subject: ipsec config problem:URGENT HELP NEEDED ... I need some help for this ipsec tunnel configuration that i am trying to ... also the configuration needs a tunnel src address and tunnel dest address. ...
    (Focus-SUN)
  • Re: Wifi ipsec freebsd
    ... I too have set up a ipsec secured wireless network and this article ... Tunnel vs. transport mode was something I never fully understood. ... connection over wifi between a FreeBSD gateway and a Windows laptop. ...
    (freebsd-questions)
  • Re: freebsd-security Digest, Vol 201, Issue 2
    ... freebsd vpn server behind nat dsl router ... which allows IPSec tunnels to be established if there is some NAT ... I have created an esp tunnel between my two sites, ...
    (FreeBSD-Security)
  • RE: IPSec vs. IPSec/L2TP
    ... The reason people use L2TP is due the need to provide login mechanism ... logging and the rest of the session would be using IPSec. ... > L2TP/IPSec tunnelling instead of a good old IPSec tunnel. ... Earn your MS in Information Security ONLINE ...
    (Security-Basics)