Click here to get back home

Applying IPSec Policy

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Applying IPSec Policy SBN via WinServerKB.com 04-06-2007
Posted by SBN via WinServerKB.com on April 6, 2007, 12:34 pm
Please log in for more thread options
Hey guys i created and enabled a sample IPSec policy in our test lab DC and
connect 1 computer to the domain. i tried to ping the IP address of the DC
and says "Negotiating IP Security" and after a few pings it became successful.
..i thought this was now ok so i restarted the PC and logon again on the
domain. i tried to ping the domain again and it says "Negotiating IP
Security" and its been 30 minutes and it still keeps Negotiating IP Security..
.

--
Message posted via WinServerKB.com
http://www.winserverkb.com/Uwe/Forums.aspx/windows-server-security/200704/1


Posted by S. Pidgorny on April 6, 2007, 8:27 pm
Please log in for more thread options
How simple is your simple policy? I mean, if you require Kerberos
authentication, and your DC (which is also KDC, the Kerberos Distribution
Center) requires IPsec to connect to it, then no one will be able to
connect, as KDC isn't available.

Details here: http://support.microsoft.com/kb/254949

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Hey guys i created and enabled a sample IPSec policy in our test lab DC
> and
> connect 1 computer to the domain. i tried to ping the IP address of the DC
> and says "Negotiating IP Security" and after a few pings it became
> successful.
> ..i thought this was now ok so i restarted the PC and logon again on the
> domain. i tried to ping the domain again and it says "Negotiating IP
> Security" and its been 30 minutes and it still keeps Negotiating IP
> Security..
> .
>
> --
> Message posted via WinServerKB.com
> http://www.winserverkb.com/Uwe/Forums.aspx/windows-server-security/200704/1
>



Posted by SBN via WinServerKB.com on April 7, 2007, 10:43 am
Please log in for more thread options
S. Pidgorny <MVP> wrote:
>How simple is your simple policy? I mean, if you require Kerberos
>authentication, and your DC (which is also KDC, the Kerberos Distribution
>Center) requires IPsec to connect to it, then no one will be able to
>connect, as KDC isn't available.
>
>Details here: http://support.microsoft.com/kb/254949
>
>> Hey guys i created and enabled a sample IPSec policy in our test lab DC
>> and
>[quoted text clipped - 6 lines]
>> Security..
>> .

- my simple policy is very similar to the built-in secure server policy
- i checked the link that you have provided....and its my understanding that
IPSec communication is not support between domain clients and domain servers..
is it?

--
Message posted via WinServerKB.com
http://www.winserverkb.com/Uwe/Forums.aspx/windows-server-security/200704/1


Posted by S. Pidgorny on April 7, 2007, 7:08 pm
Please log in for more thread options
...only when you apply the IPSec policies by using Group Policy or when you
use the Kerberos version 5 protocol authentication method. Use certificates
or manually configured policies and you'll be fine.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> S. Pidgorny <MVP> wrote:
>>How simple is your simple policy? I mean, if you require Kerberos
>>authentication, and your DC (which is also KDC, the Kerberos Distribution
>>Center) requires IPsec to connect to it, then no one will be able to
>>connect, as KDC isn't available.
>>
>>Details here: http://support.microsoft.com/kb/254949
>>
>>> Hey guys i created and enabled a sample IPSec policy in our test lab DC
>>> and
>>[quoted text clipped - 6 lines]
>>> Security..
>>> .
>
> - my simple policy is very similar to the built-in secure server policy
> - i checked the link that you have provided....and its my understanding
> that
> IPSec communication is not support between domain clients and domain
> servers..
> is it?
>
> --
> Message posted via WinServerKB.com
> http://www.winserverkb.com/Uwe/Forums.aspx/windows-server-security/200704/1
>



Similar ThreadsPosted
Help! Group policy not applying to computer in OU September 30, 2008, 2:15 pm
Error 0x800704b8 when applying policy with Security Configuration Wizard March 28, 2007, 6:30 pm
Creating IPSec Policy for Pre-Share Key in VPN not working. October 25, 2005, 6:31 am
IPSec policy on servers connected to 2 networks November 18, 2007, 1:08 pm
Event ID 1202 when applying new GPO June 13, 2006, 3:31 pm
Applying Permissions and Inheriting October 13, 2006, 11:46 am
NTFS permissions not applying consistently June 21, 2006, 12:16 pm
Applying SAFER policies via GPO, is this the right newsgroup to post in March 27, 2006, 2:35 am
Applying Security Template to Every User's Folder Structure January 10, 2007, 11:31 pm
Applying Windows 2003 policies to Windows XP June 24, 2008, 2:34 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap