ipsec filter shooting ads in foot?

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: frank brown (someone_at_somewhere.net)
Date: 07/08/04


Date: Thu, 08 Jul 2004 19:33:09 GMT

I created an ipsec policy which blocks all incoming traffic except for http,
https, and rdp (per MS official hands-on lab 2811: applying microsoft
security guidance, appendix a) and applied this policy to a server. Now I
am unable to connect to this server; it appears to be blocking ADS
authentication. If this is the case, when I deassign the blocking ipsec
policy, will it actually be deassigned or will the server block the message
which would deassign it? Has this server gotten into an ipsec black hole?

-Frank Brown
http://www.inwa.net/~frog/



Relevant Pages

  • Re: Securing the communication between all workstations in a domain
    ... I am no expert at Ipsec. ... I would try using the server (request ... security) policy in that OU - the secure policy is rather extreme and can ... exempt the domain controllers from ipsec traffic - a request policy may work ...
    (microsoft.public.win2000.security)
  • Re: Require connecting systems to be a Domain Computers
    ... something in which I include the group Domain Computers. ... >kerberos computer authentication for the ipsec SA then the computer must be ... In such case the server must not be a domain controller, ... >ipsec require policy will need to exempt all domain controllers with a rule ...
    (microsoft.public.security)
  • Re: lan ipsec ws2003 / xp pro deplyoyment
    ... Remote Access on the server and configure it and then configure your XP computer to ... preshared key for machine authentication. ... If you use ipsec pre shared key [policy/all ... You could go to Local Security Policy of each ...
    (microsoft.public.windowsxp.security_admin)
  • Re: IPSEC Problems
    ... You may want to try and rebuild the ipsec policy. ... ipsec negotiation traffic between domain members and domain controllers as ... > this server and any communication was shown correctly in ipsecmon. ...
    (microsoft.public.windows.server.security)
  • Re: IPSec Policy Doesnt Really Block
    ... Group Policy would be one way to apply ipsec policies. ... by now I would double check the dns configuration on that server making sure it ... >> where specific filters override general filters where there is a conflict. ...
    (microsoft.public.win2000.security)