Re: AD replication security

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Jeromy Statia [MSFT] (jstatia_at_online.microsoft.com)
Date: 02/05/04


Date: Thu, 5 Feb 2004 13:46:09 -0800

if working with windows 2000 DC's refer to the following article:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;254949
Client-to-Domain Controller and Domain Controller-to-Domain Controller IPSec
Support
but pay close attention to
http://support.microsoft.com/default.aspx?scid=kb;EN-US;254728
IPSec Does Not Secure Kerberos Traffic Between Domain Controllers

when running Server 2003 please note the following articles:

http://support.microsoft.com/?kbid=810207
IPSec Default Exemptions Are Removed in Windows Server 2003

also the following link has some very interesting information on IPSec and
windows server 2003
http://www.serverwatch.com/tutorials/article.php/3109971

Hope this helps out and answers your questions

tx

-- 
Jeromy Statia [MSFT]
This posting is provided "AS IS" with no warranties, and confers no rights.
"Michael ray" <anonymous@discussions.microsoft.com> wrote in message
news:aa2501c3ebf1$15f6d710$a501280a@phx.gbl...
> HI
>
> I would like to secure AD replication between DC`s with
> IPSEC, what is the best way to it ??
> Should i secure only the replication ports or the entire
> communication between the DC`s ??
>
> Any other suggestions for replication security ???


Relevant Pages

  • Re: IPSEC, W2k3, Client-to-DC
    ... Microsoft Windows Networking ... > I remember for Windows 2000, IPSEC was not recommended to be used to ... > traffic between client to domain controllers, ...
    (microsoft.public.windows.server.security)
  • Re: Ace Password Sniffer : How does it work ?
    ... >> Another protocol that offers same is IPSec. ... >> authentication and secure transfer of data between server and client ... >> would be pretty hard to use SSL to secure data exchanged between ... Once you are done with the secured login, ...
    (microsoft.public.security)
  • Re: can xp act as server for vpn connection
    ... IPSEC L2TP connections won't work behind a NAT firewall without ... included in Windows XP... ... >>you can set the security policy on the client connection. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Securing Communication Between Domain Members and their Domain Controllers
    ... look into using an ipsec tunnel into a gateway computer or ipsec endpoint device or ... > located stand alone servers. ... > integrte them into a single secure Active Directory Domain. ... > member servers to communicate this way, looking through the MS tech. support ...
    (microsoft.public.win2000.security)
  • RE: Passwords with Lan Manager (LM) under Windows
    ... IPsec does (or at least can and I am not going into a page of detail to ... authenticating the client system ... Passwords with Lan Manager under Windows ...
    (Pen-Test)