Re: Blocking by MAC Address -



Hi,

You don't have to use encryption. You can set up ESP-Null. In this case
packets only get authenticated. This will still add up a bit to the
processor since it has to check every packet but this will in general be few
percents (3-5). Most of server's CPU is more or less below 10% so adding
3-5% should not be a problem.

--
Mike
Microsoft MVP - Windows Security

"FabrizioV" <FabrizioV@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7037C317-BE2F-4ECC-9CB1-3C42882E71BB@xxxxxxxxxxxxxxxx
> Good morning Mike.
> The article is really interesting and IPSEC is an option to consider.
> An issue (IMHO) is the overhead you'll have on the clients and (most
> important) on the servers, when you encrypt all the traffic on your
> network.
> As you can see in this article :
> http://www.microsoft.com/technet/community/chats/trans/network/net0610.mspx
>
> "CPU on servers can be a problem but it can be mitigated by using IPSEC
> offload card from vendors like 3COM and Intel."
>
> So, if you already have or you are going to buy SSL/IPSEC dedicated cards
> for your data center IPSEC is a good choice.
> Else, if you have Windows 2003 and 802.1x enabled network switches, dot1x
> should be your choice.
>
> Fabrizio Volpe
>
>
> "Miha Pihler [MVP]" wrote:
>
>> Hi,
>>
>> Mitigating the Threats of Rogue Machines-802.1X or IPsec?
>> http://www.microsoft.com/technet/community/columns/secmgmt/sm0805.mspx
>>
>> --
>> Mike
>> Microsoft MVP - Windows Security


.



Relevant Pages

  • RE: Secure / Encrypt Terminal Services
    ... Terminal Services does have decent encryption, ... IPSec is a great solution. ... As for the encryption, I do feel somewhat safe using the built-in ... I would certainly consider additional security. ...
    (Focus-Microsoft)
  • Re: "Linux Shminux - IPsec is Snake Oil!" VMS Mgmnt
    ... In addition to the Apple, IBM, SUN, Microsoft, and HP-UX support for IPsec I ... This was a public company which needed to meet Sarbanes-Oxley regulations and auditing, most of which covered security. ... I couldn't say whether IPSEC or some other form of encryption was really needed or not but I'm reasonably certain that none of my jobs since being discharged from the Army in 1969 used any form of encryption for internal network traffic. ...
    (comp.os.vms)
  • Re: Interaction between ipfw, IPSEC and natd
    ... > which means that NAT is extremely hard to use in an IPSEC environment. ... do not need IPSEC packets to be routed through the firewall at all. ... 'untrusted IPSEC tunnel' (that is, a tunnel which you want to filter traffic ...
    (FreeBSD-Security)
  • Re: Interaction between ipfw, IPSEC and natd
    ... >> which means that NAT is extremely hard to use in an IPSEC environment. ... > do not need IPSEC packets to be routed through the firewall at all. ... > and dest address and injects it into the outside interface of the firewall; ...
    (FreeBSD-Security)
  • Re: IPSec to encrypt SMB traffic?
    ... Can Etercap sniffer/interceptor defeat IPSec? ... > particular Windows 2003 file server. ... Removed all entries under Key Exchange Security Method except ... > Encryption and Integrity Security Method. ...
    (microsoft.public.windows.server.security)

Loading