Re: Microsoft Strategic Technology Protection Program

From: Jean-Baptiste Marchand (Jean-Baptiste.Marchand@HSC.FR)
Date: 10/10/01


Message-ID:  <20011010132234.A27137@garbarek.hsc.fr>
Date:         Wed, 10 Oct 2001 13:22:34 +0000
From: Jean-Baptiste Marchand <Jean-Baptiste.Marchand@HSC.FR>
Subject:      Re: Microsoft Strategic Technology Protection Program
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Tony Chow <tchow@BLUETENTACLE.COM> wrote :

[...]

> Another potential area of confusion lies in IPSec. IPSec is not as
> capable as a firewall. It cannot distinguish between incoming and
> outgoing TCP traffic, and between the various types of ICMP messages.

AFAIK, IPsec filters can distinguish incoming and outgoing trafic.
However, the default setting when specifying a filter in the 'IP
Security Policies' plugin in the MMC is 'Mirrored' (equivalent to a '+'
instead of '=' when specifying rule via ipsecpol), whose immediate
effect is to effectively produce two rules, for incoming and outgoing
trafic. You can uncheck this option and specify different rules for
inbound and outbound trafic.

On the other hand, if you need to filter on ICMP messages (type and
code), you can use the packet filtering possibilites of the RRAS
service. You can script these rules via netsh. If you are only
interested in IP filtering of RRAS, maybe you'd prefer to use a small
service that can configure the IP filtering driver found in Windows
2000 instead of RRAS

<advertisement>
PktFilter (http://www.hsc.fr/ressources/outils/pktfilter/) can configure
the IP filter driver of Windows 2000, using rules written in a text file
</advertisement>

However, I'm not sure if you can deploy RRAS IP filtering rules as
easily as IPsec policies.

Hope this helps,

Jean-Baptiste Marchand

--
Jean-Baptiste.Marchand@hsc.fr
Hervé Schauer Consultants
http://www.hsc.fr/

============================================================================ Delivery co-sponsored by Trend Micro, Inc. ============================================================================ BEST-OF-BREED ANTIVIRUS SOLUTION FOR MICROSOFT EXCHANGE 2000 Earn 5% rebate on licenses purchased for Trend Micro ScanMail for Microsoft Exchange 2000 between October 1 and November 16. ScanMail ensures 100% scanning of inbound and outbound traffic and provides remote software management. For program details or to download your 30-day FREE evaluation copy: http://www.antivirus.com/banners/tracking.asp?si=53&BI;=245&UL;=http://www.ant ivirus.com/smex2000_rebate



Relevant Pages

  • Re: Recurrent question
    ... Here the ICF can be enabled manually - or the filtering stuff, ... which is called "IPSec" by Microsoft. ... "Ich bin ein freier Mensch und werde jetzt von meinen Freiheitsrechten ...
    (comp.security.firewalls)
  • Re: POP3 connector retrieves only 99 emails at once
    ... > on SBS 2003 we have no such filter or software can be used to block POP3 ... > that there are filtering rules in send filtering section and connection ... > Microsoft Exchange Intelligent Message Filter Deployment Guide ... > This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: POP3 connector retrieves only 99 emails at once
    ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... |> spam emails from ISP, you have to use some third party tools to achieve ... |> that there are filtering rules in send filtering section and connection ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS 2003 SP1 and Exchange SP2
    ... non-linked attributes stored in an Active Directory object exceeds the ... And there is another possible workaround, that is instead of filtering on ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: TCP/IP Filtering Question
    ... Steve's advice to use IPSec is excellent and far to few ... Ipsec filtering will not block multicast and broadcast traffic, ... > For what you are doing you might want to try ipsec filtering policy using> permit and block fitter actions instead on that router computer. ... If you do> not want the same ipsec policy applied to both adapters, then configure the> actual IP address of the network adapter you want to filter instead of "my ...
    (microsoft.public.win2000.networking)