Re: sysvol replication breaks when IPSec running between DCs & fir
- From: v-mileli@xxxxxxxxxxxxxxxxxxxx (Miles Li [MSFT])
- Date: Mon, 19 Jan 2009 10:31:36 GMT
Hello,
Thanks for the update.
Yes, to allow the IPSec traffic ports and protocols for IPSec should be
allowed on the network device. The "Firewall" mentioned in the TechNet
article means the firewall that lays between the 2 (or more) DCs that use
IPSec to encrypt the traffic instead of the Windows Firewall.
In the Windows TCP/IP Architecture, IPnat.sys (Windows firewall) is always
processed after IPsec.sys. You may check the following article to get an
idea of the Windows TCP/IP Packet Processing Paths.
The Cable Guy - June 2005--->TCP/IP Packet Processing Paths
http://technet.microsoft.com/en-us/library/bb878072.aspx
In this issue, I think the FRS traffic is blocked by the Windows Firewall.
You may have a test to temporarily disable the Windows Firewall on all DCs
to check how it works. In the scenarios that you need the Windows Firewall
enabled on the DC, you can enable the Windows Firewall:Allow authenticated
IPSec bypass" policy to bypass the IPsec traffic for Domain Controller
group in the Windows Firewall.
Hope it helps. If you have any questions or concerns, please do not
hesitate to let me know.
Best regards,
Miles Li
Microsoft Online Partner Support
Microsoft Global Technical Support Center
Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
.
- Follow-Ups:
- References:
- sysvol replication breaks when IPSec running between DCs & firewal
- From: brad
- Re: sysvol replication breaks when IPSec running between DCs & firewal
- From: Meinolf Weber [MVP-DS]
- Re: sysvol replication breaks when IPSec running between DCs & firewal
- From: Miles Li [MSFT]
- Re: sysvol replication breaks when IPSec running between DCs & fir
- From: brad
- sysvol replication breaks when IPSec running between DCs & firewal
- Prev by Date: Re: Preventing logon to local accounts
- Next by Date: Re: Preventing logon to local accounts
- Previous by thread: Re: sysvol replication breaks when IPSec running between DCs & fir
- Next by thread: Re: sysvol replication breaks when IPSec running between DCs & fir
- Index(es):
Relevant Pages
|
Loading