Click here to get back home

IPSec Kerberos issue?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
IPSec Kerberos issue? Dan 03-19-2007
Posted by Dan on March 19, 2007, 9:39 pm
Please log in for more thread options
I have a windows 2003 domain. I have 2 Servers that are both in the same
domain.

I have a filter requiring ESP (3DES/SHA1) only for communications on port 80
+ 25 between these 2 servers.

When I use kerberos for authentication... authentication fails. When I
switch the authentication method to use a preshared key for authentication,
everything works perfectly.

DNS is working fine. The servers resolve each other and the DC properly.
Logging into the servers works properly, and normal kerberos auth doesn't
seem to cause problems/errors.


#####
IKE security association negotiation failed.
Mode:
Key Exchange Mode (Main Mode)

Filter:
Source IP Address XX.XXX.XXX.XX
Source IP Address Mask 255.255.255.255
Destination IP Address XX.XXX.XXX.XX
Destination IP Address Mask 255.255.255.255
Protocol 0
Source Port 0
Destination Port 0
IKE Local Addr XX.XXX.XXX.XX
IKE Peer Addr XX.XXX.XXX.XX
IKE Source Port 500
IKE Destination Port 500
Peer Private Addr

Peer Identity:
Kerberos based Identity: servername$@domain.COM
Peer IP Address: XX.XXX.XXX.XX

Failure Point:
Me

Failure Reason:
Negotiation timed out

Extra Status:
Processed first (SA) payload
Initiator. Delta Time 62
0x0 0x0
#####

I've followed the MS troubleshooting docs, (disabled any offloading), and
verified that there are not errors in the AD logs.

Any help/ideas would be GREATLY appreciated.



Similar ThreadsPosted
IPSec and Kerberos September 27, 2006, 10:17 am
sharePoint and kerberos November 6, 2005, 5:35 pm
Kerberos delegation December 7, 2006, 12:53 pm
[Q] Kerberos DES encryption April 20, 2007, 6:11 am
Kerberos headache February 1, 2008, 7:33 am
LSASS & Kerberos Documentation July 8, 2005, 11:35 am
Kerberos/ASP/Delegation/W2K3 July 19, 2005, 2:24 pm
How to set up Kerberos authentication? (some code :) August 18, 2005, 2:55 pm
Win2k3/IIS Kerberos challenges December 22, 2005, 1:42 pm
Kerberos and HOST Headers December 31, 2005, 6:40 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap