RE: Using IPSEC to block IP

From: Jeroen Beekhuis (j.beekhuis@uci.kun.nl)
Date: 08/21/01


From: "Jeroen Beekhuis" <j.beekhuis@uci.kun.nl>
To: "'Tom Geldner'" <tom@xor.cc>, <wb4-users@forums.chatspace.com>
Subject: RE: Using IPSEC to block IP
Date: Tue, 21 Aug 2001 11:31:55 +0200
Message-ID: <11673C05E27BD311945000508B2C1DF99CCDB9@kunuci05.uci.kun.nl>


> I want to be able to block two static IPs from being able to transact
> anything with either IIS or WebBoard. I know I can do it internally on
> IIS but WebBoard doesn't have any built-in IP filtering (that
> I'm aware
> of). So I'd prefer to do both at once on a lower level.
>
> So it sounds like IPSEC is the way to go. Help?
>
> Tom
>

Hi Tom,

I use the IPSec settings to assign complete packet filter settings to a hurd
of Win2K webservers, using active dir policies. It's a bit tricky at first,
but now I could block a host or subnet and have al systems apply the new
settings within a minute. The settings I use apply to normal IP traffic,
using IPSec encyption is an option.
You DO need an Active Direcotry in place, otherwise centralized policies
won't work. If you dont't, using local policies should also do the trick.
Since this built-in mechanism doesn't log anything, we use snort as an IDS
(on Win2K) for that.

Jeroen Beekhuis.



Relevant Pages

  • Verify IPSec policies are running on XP and 2003
    ... IP Sec policy "Request Security" was created and linked as follows: ... RSOP on the XP box under the admin account doesn't display IPSec ... Running it for the Test user also shows no IP settings. ... ACL's on the policies appear correct. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Server 2003 IPSec VPN
    ... I take it you used a ipsec tunneling policy and did not use Remote Access ... key lifetimes on the Windows 2003 Server it would not reset that often and I ... I do not have any rekey parameter settings configured on the ...
    (microsoft.public.windows.server.security)
  • Re: Configuring a VPN client for a dlink dfl800 firewall
    ... If you failed post what you have ... tried exactly, what settings you have used, what exact error messages ... I need to check again all the settings (IPSec ...
    (comp.security.firewalls)
  • Re: ipsec ISA to Watchguard
    ... While I'm not doing a IPSec to a ISA server, ... IP Address of other device/fw (Public) ... Remote (IP Subnet of LAN side) ... SA Settings ...
    (comp.security.firewalls)
  • Re: ipsec ISA to Watchguard
    ... While I'm not doing a IPSec to a ISA server, ... Remote Gateway: IP Address of other device/fw ... Remote (IP Subnet of LAN side) ... SA Settings ...
    (comp.security.firewalls)