Using IPSec as a Packet Filter Firewall

From: Forrester, Mike (mforrester@hsacorp.net)
Date: 08/26/01


Message-ID: <A2DD4A0747C2D41189F400B0D03E46C61D877F@hsadenmx06.hsacorp.net>
From: "Forrester, Mike" <mforrester@hsacorp.net>
To: "'focus-ms@securityfocus.com'" <focus-ms@securityfocus.com>
Subject: Using IPSec as a Packet Filter Firewall
Date: Sat, 25 Aug 2001 20:41:13 -0600

Greetings,
I am in the process of starting my practical for the GIAC NT Security
certification and decided on the topic of how to use the IPSec filters on
Windows 2000 as a packet filtering firewall. I'll probably talk about it in
a defense-in-depth approach and only as a host-based firewall (not as router
or gateway). Does anyone have any recommendations on books, white-papers,
websites, etc. that cover IPSec packet filtering on Windows 2000 in detail?
I'm looking for information on rule ordering, known limitations, bugs, etc.,
not on how to create rules or about IPSec for encryption. I know the IPSec
filtering on Windows 2000 still leaves a lot to be desired (state,
fragmentation, and flag checking; logging; etc.), but due to the lack of
knowledge on this aspect of IPSec on Windows 2000, it seems like a good
topic.

Now before everyone goes on about the pros or cons of Windows, packet
filters, etc., understand that the purpose of my research and paper is to
get a good understanding of IPSec packet filtering on Windows 2000. Not
network design, defense-in-depth, or any other religious security topic. I
plan to cover these topics on a basic level in my paper, but just enough to
compliment the subject.

Thanks in advance,
Mike



Relevant Pages

  • RE: ip filters and blackice
    ... This is a good article, however, it is important to know the limitations of ... IPSec is not designed for packet filtering, ... allowing 'any' port on your IP to connect with '25' on the dest IP. ...
    (Focus-Microsoft)
  • Re: With or without IPSEC
    ... IPsec encompasses ... One use for IPsec in Windows 200 is port and ... sort of packet filtering is usually better than none at all, ... filtering set up also on incoming VPN connections, ...
    (microsoft.public.win2000.security)
  • Re: zonealarm problem
    ... the Windows-Firewall is a good solution; there is packet filtering ... have to deal with this "IPSec" stuff of Windows; this is it's name, ... of the fact, that packet filtering has nothing to do with IPSec, though). ...
    (comp.security.firewalls)
  • Re: IP Packet filtering using online blocklists
    ... XP supports IPSEC packet filtering as a native service, ... online site that supports Windows IPSEC file formats. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: FTP and Packet Filtering
    ... I hope your packet filtering has logging as well. ... win2000 ipsec it doesn't. ... There are at least two kinds of FTP, ... The other uses 21 and a high TCP port determined on the ...
    (microsoft.public.inetserver.iis.security)