Click here to get back home

IPSec policy on servers connected to 2 networks

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
IPSec policy on servers connected to 2 networks Stuart 11-18-2007
Posted by Stuart on November 18, 2007, 1:08 pm
Please log in for more thread options
Hi. I am currently investigating how to setup an IPSec policy on a small
network (single domain) of ~20 windows 2003 and 2000 servers and ~10 windows
xp and 2000 workstations. Of the 20 servers 5 of them are directly
connected to other networks via a second nic, the IP address ranges of these
second network connections also vary.

If possible can anyone advise how I can deploy a policy to enable IPSec on
the internal domain traffic while still allowing these 5 servers to continue
communicating to their second network in the clear ? I'm comfortable with
setting up IPSec, it's how to handle the two network issue I'm stuck on.

Thanks,
Stuart.


Posted by Steve Riley [MSFT] on November 19, 2007, 11:20 pm
Please log in for more thread options
Except for when you indicate the interface type (all, LAN, or remote), the
IPsec engine doesn't care about interfaces -- it concerns itself only with
IP addresses and any rules that match those addresses.

What kind of policies do you want on the internal domain?


--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


"Stuart" <newsgroups> wrote in message
> Hi. I am currently investigating how to setup an IPSec policy on a small
> network (single domain) of ~20 windows 2003 and 2000 servers and ~10
> windows xp and 2000 workstations. Of the 20 servers 5 of them are
> directly connected to other networks via a second nic, the IP address
> ranges of these second network connections also vary.
>
> If possible can anyone advise how I can deploy a policy to enable IPSec on
> the internal domain traffic while still allowing these 5 servers to
> continue communicating to their second network in the clear ? I'm
> comfortable with setting up IPSec, it's how to handle the two network
> issue I'm stuck on.
>
> Thanks,
> Stuart.


Posted by Roger Abell [MVP] on November 20, 2007, 10:59 am
Please log in for more thread options
Instead of defining your rules as to/from My Address define
them using to/from IP of concern for the traffic type.

"Stuart" <newsgroups> wrote in message
> Hi. I am currently investigating how to setup an IPSec policy on a small
> network (single domain) of ~20 windows 2003 and 2000 servers and ~10
> windows xp and 2000 workstations. Of the 20 servers 5 of them are
> directly connected to other networks via a second nic, the IP address
> ranges of these second network connections also vary.
>
> If possible can anyone advise how I can deploy a policy to enable IPSec on
> the internal domain traffic while still allowing these 5 servers to
> continue communicating to their second network in the clear ? I'm
> comfortable with setting up IPSec, it's how to handle the two network
> issue I'm stuck on.
>
> Thanks,
> Stuart.



Similar ThreadsPosted
How to Fix: Anonymous Session Connected; Attempted to Open an LSA Policy Handle. Event 6033 September 26, 2007, 4:41 pm
Win2003 Servers hidden from Network Browse list when using IPSec September 12, 2006, 3:39 pm
Applying IPSec Policy April 6, 2007, 12:34 pm
Creating IPSec Policy for Pre-Share Key in VPN not working. October 25, 2005, 6:31 am
Microsoft Executive Circle Webcast: Security360 with Mike Nash: Building a Secure, Connected Infrastructure with Digital Certificates April 18, 2006, 7:25 am
ipsec October 29, 2005, 4:21 am
OSX and Ipsec September 17, 2006, 11:14 pm
IPSec September 12, 2007, 6:33 pm
Servers in two Vlans October 26, 2005, 8:00 am
using web enrollment for servers etc. February 11, 2008, 2:44 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap