IPSEC Failing (Secure Server)

From: Aaron (Aaron_at_discussions.microsoft.com)
Date: 11/17/04


Date: Wed, 17 Nov 2004 13:28:01 -0800

Server A has local policy configured as Secure Server(Require Security).
Client B has local policy configured as Client(Respond Only). Both A and B
are members of the same W2K3 AD domain. Event log error on Server A: IKE
security ssociation failed: Key Exchange Mode (Main Mode). Further down it
says, Failure Point: Me, Failure Reason: Failed to authenticate using
kerberos.

Doing some trouble shooting, I found that if I changed the policy on Server
A to Server(Request Security) the communication did occur and was
encapsulated (verified using NetMon). I also could get this to work if,
leaving the policy on Server A on Secure Server, I changed the policy on
Client B to Server(Request Security).



Relevant Pages

  • Re: write with cURL
    ... It takes time to set up an account for you, process the billing, etc. ... Sorry, my servers are secure. ... Nothing you have told me shows me you know how to lock down a server so that it is secure - other than to use the server's file security. ...
    (alt.php)
  • "An Asp.Net accident waiting to happen" - Draft article
    ... In a time where Security ... in shared hosting environments. ... technologies that allow the creation and deployment of secure ... IIS 6 web server and windows 2003 also provide some tools to deploy ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: UnauthorizedAccessException when using MSDTC
    ... dispatcher2 is the user logged on the client pc. ... Event Source: Security ... Object Server: SC Manager ... Primary Domain: BLITZ ...
    (microsoft.public.data.ado)
  • Re: Routing and Remote Access - Authentication Failure
    ... because the real client computer can tunel through it's local NAT router, ... travel the Intrenet, join the VPN and access the server, when this feature ... Their security system decided that the server was trying to steel ...
    (microsoft.public.windows.server.networking)
  • Re: WCF security advice (and clarification) needed
    ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
    (microsoft.public.dotnet.framework.webservices)