Click here to get back home

IPSec tunnels win2003 server

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
IPSec tunnels win2003 server Henrik 01-04-2006
Posted by Henrik on January 4, 2006, 8:01 am
Please log in for more thread options
setup:

LAN 1: (10.10.10.0/255.255.255.0)
Gateway: 10.10.10.254/255.255.255.0
server1 (win2003SP1):
NIC1.1: 10.10.10.1/255.255.255.0
NIC1.2: 99.99.99.91 (MPLS adress)

LAN 2: (10.10.20.0/255.255.255.0)
Gateway: 10.10.20.254/255.255.255.0
server2(win2003SP1):
NIC2.1: 10.10.20.1/255.255.255.0
NIC2.2: 99.99.99.92 (MPLS Adress)

LAN1 is connected to LAN2 throug a LAN-2-LAN VPN tunnel (CISCO PIX)
througput 10MBit

Server1-NIC1.2 is connected to server2-NIC2.2 throug a 1GBit MPLS Network

Is it posible to shield of NIC1.2 and NIC2.2 so the only trafic allowed on
the NICs is incomming/outgoing IPSec tunnels between the 2 servers. and when
the tunnel is established only trafic on a few ports is allowed.

Any hints?


Posted by Steven L Umbach on January 4, 2006, 4:48 pm
Please log in for more thread options
I have not tried it myself but you might be able to make it work. Configure
your ipsec policy filters so that instead of using "my IP address" you use
the actual IP address of the network adapter. You can specify
ports/protocols in the filters. The link below may help. --- Steve

http://www.microsoft.com/technet/security/topics/architectureanddesign/ipsec/ipsecapa.mspx

> setup:
>
> LAN 1: (10.10.10.0/255.255.255.0)
> Gateway: 10.10.10.254/255.255.255.0
> server1 (win2003SP1):
> NIC1.1: 10.10.10.1/255.255.255.0
> NIC1.2: 99.99.99.91 (MPLS adress)
>
> LAN 2: (10.10.20.0/255.255.255.0)
> Gateway: 10.10.20.254/255.255.255.0
> server2(win2003SP1):
> NIC2.1: 10.10.20.1/255.255.255.0
> NIC2.2: 99.99.99.92 (MPLS Adress)
>
> LAN1 is connected to LAN2 throug a LAN-2-LAN VPN tunnel (CISCO PIX)
> througput 10MBit
>
> Server1-NIC1.2 is connected to server2-NIC2.2 throug a 1GBit MPLS Network
>
> Is it posible to shield of NIC1.2 and NIC2.2 so the only trafic allowed on
> the NICs is incomming/outgoing IPSec tunnels between the 2 servers. and
> when
> the tunnel is established only trafic on a few ports is allowed.
>
> Any hints?
>



Similar ThreadsPosted
Win2003 Servers hidden from Network Browse list when using IPSec September 12, 2006, 3:39 pm
Win2003 Server - 10,000 Entries ! February 9, 2006, 11:28 pm
Lockdown on 2nd NIC card on WIN2003 Server March 6, 2006, 3:01 pm
How to setup Win2003 as a proxy server ? October 13, 2006, 3:32 pm
Folder permissions on Win2003 server February 13, 2007, 1:21 pm
Win2003 Server automated password changes. What about Mac clients March 7, 2008, 12:32 pm
file server move from win2000 to win2003 April 24, 2008, 9:50 pm
HELP! Error /w Wireless Client Connecting to Win2003 Server /w IAS, CA November 12, 2005, 4:31 pm
Bizarre File Security Issue in Win2003 server January 12, 2006, 9:50 am
Are there any GROUPs created automatically by installing Cert Server in Win2003? November 14, 2006, 11:34 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap