IPSec filtering vs. VPN

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Michael A. Covington (look_at_www.ai.uga.edu.for.information)
Date: 06/16/04


Date: Wed, 16 Jun 2004 18:17:03 -0400

Greetings,

I am using Microsoft IP Security Policy (on a Windows 2003 server) to drop
unwanted TCP packets like a firewall, as described here:

http://www.microsoft.com/technet/itsolutions/network/security/ipsecld.mspx

My problem is that one of my servers is hosting a VPN (through RRAS), and no
matter what I do, I can't find a setting (other than "allow everything")
that makes the VPN usable.

I tried the following filter set:

Port 1723 protocol TCP from any IP address to my IP address
Port ANY protocol 47 from any IP address to my IP address
Filter action: Permit

That didn't work. Nor did using UDP port 47 in place of any port protocol
47.

What are the correct settings? My server hosts the VPN by means of 2
network cards; am I maybe applying the settings to the wrong card?

The settings applied to all the other port numbers (to permit HTTP, FTP,
etc., and block other things) are working as advertised.

Many thanks!



Relevant Pages

  • Re: Cant Send e-mails - Outlook 2003
    ... Rich, the answer to #1 is yes, at home Outlook sends messages just fine. ... I asked them about other port numbers, and they say they do not have any ... Your original settings might have been okay, but Verizon may have had server ...
    (microsoft.public.outlook.installation)
  • IPSec filtering vs. VPN
    ... I am using Microsoft IP Security Policy (on a Windows 2003 server) to drop ... unwanted TCP packets like a firewall, ... Port 1723 protocol TCP from any IP address to my IP address ... What are the correct settings? ...
    (microsoft.public.windows.server.security)
  • IPSec filtering vs. VPN
    ... I am using Microsoft IP Security Policy (on a Windows 2003 server) to drop ... unwanted TCP packets like a firewall, ... Port 1723 protocol TCP from any IP address to my IP address ... What are the correct settings? ...
    (microsoft.public.win2000.security)
  • Re: Desktop On-Call
    ... Also, if your port wasn't opened in a firewall, then I don't think you'd get the login prompt. ... I think the login Java applet does some initial communication with the DTOC server before it asks for your username and password. ... The notebook settings for this are found in the "Host PC Setting" tab. ...
    (comp.os.os2.apps)
  • Re: Need to download Microsoft Outlook 2000 SR-1
    ... server settings there. ... email acct your having problems with. ... a time> Select Properties button> Server tab> In the b. ... In the Outgoing Port setting use 465, ...
    (microsoft.public.outlook.installation)