Problem - Using IPSec to secure Windows Messenger Traffic

From: Burak Bayoglu (bayoglu@uekae.tubitak.gov.tr)
Date: 05/28/02


From: "Burak Bayoglu" <bayoglu@uekae.tubitak.gov.tr>
To: <focus-ms@securityfocus.com>
Date: Tue, 28 May 2002 16:09:05 +0300


We have problems with encrypting Windows Messenger traffic with Windows
IPSec. First of all did anybody succeed to encrypt this traffic ?
assuming you want to know about our exchange-messenger configuration and
IPSec policy, I give it below :

Clients' OS : Windows XP
Exchange Server 2000 OS(also DC): Advanced Server SP2

Communication occurs between clients and server through ports:

1. clients' any port to exchange's tcp:80
2. echange's any port to clients' tcp:12345 (fixed incoming client port)

the real problem is : we succeeded to encrypt the connections mentioned
above and successfully tested it with telnet connections between
them.. but the messenger client program neither can not sign in nor send
a message.

Does anyone have an idea about the situation? May there be something
working below IPSec layer about Windows Messenger or did anyone meet any
similar problem with any other application while using any sort of
IPSec?

Burak Bayoglu
TUBITAK-UEKAE
WinSec Group



Relevant Pages

  • Re: [OpenVMS, DECnet] How to do DECnet over - secure (ssh, ssl) - IP ? IP ? IP ?
    ... It is the Unix style of solving problems. ... sticky tape and paperclip way of software design. ... I assume it will be possible to encrypt DECnet over IP ... > with IPsec, but alas we have to wait just a little bit longer before ...
    (comp.os.vms)
  • Multiple Gateway IPSEC Problem
    ... Cisco Router: Gateway Interface: 10.0.1.2 ... spdadd 91.18.78.0/27 91.18.78.32/27 any -P in ipsec ... # Encrypt and direct all other traffic ...
    (freebsd-net)
  • encrypt with C# and decrypt with C++
    ... application and occasionally sent to specific clients. ... and send it and can never decrypt it (even if somebody completely hacked the ... Can I use public key algorithm to encrypt using private key and give the ...
    (microsoft.public.dotnet.security)
  • Re: Verhindern, dass sich fremde Rechner im Netzwerk anmelden.
    ... weil IPSec zwischen DC's und Clients ... Dafür ist DHCP der falsche Ansatz. ... Yusuf Dikmenoglu - MVP Windows Server ...
    (microsoft.public.de.german.windows.server.active_directory)
  • RE: username and Password sent as clear text strings
    ... ipsec communication to only encrypt traffic to this particular ... What does everyone think of implementing a IPSEC solution to resolve the ... SSL was designed for client application-to-server application ... I completed a security review of a web server, ...
    (Pen-Test)