RE: Scripted IPSec policies on Windows XP (without AD/GPOs)

From: Rasmus Rønlev (rr.its_at_cbs.dk)
Date: 05/27/05

  • Next message: Thor (Hammer of God): "Re: Scripted IPSec policies on Windows XP (without AD/GPOs)"
    Date: Fri, 27 May 2005 19:08:05 +0200
    To: 'Security Focus Microsoft Mailinglist' <focus-ms@securityfocus.com>
    
    

    Hey,

    Thanks for the responses.

    First, it seems netsh ipsec (even in WinXP SP2) commands are only supported
    with Windows 2003 Server products. I did originally hope for being able to
    use netsh for scripting my way out of it - but this doesn't seem to be
    possible - at least it hasn't been on the Windows XP boxes I've checked.

    Secondly, I'm looking at the 'DCOM IPSec Mitigation Tools' that K Levinson
    suggested. I actually was made aware of ipseccmd earlier today (my email was
    sent last night my local time ;) - and have been toying around with it along
    with the IP Security Policy snap-in. I'm thinking this is the viable
    solution when combined with the information coming in the toolpack :)

    So thanks to both of you. If anyone else knows of other methods please
    enlighten me, as they might be better or easier to use!

    Regards,
    r@smus

    -----Original Message-----
    From: Brian A. Reiter [mailto:breiter@wolfereiter.com]
    Sent: 27. maj 2005 18:58
    To: 'Rasmus Rønlev'; 'Security Focus Microsoft Mailinglist'
    Subject: RE: Scripted IPSec policies on Windows XP (without AD/GPOs)

    You should look into netsh.exe. Netsh is the command-line management tool
    for all network configuration settings in Windows XP and Windows Server
    2003.

    > 1.) Is it possible either through the ‘local’ mmc based “IP
    > Security Policy”
    > or using another tool to export the given IPSec policy (for
    > importing elsewhere and/or using in a script)

    You can certainly import and export a policy with the MMC snap-in to a
    "policy file". I believe you can also import and export a policy using
    netsh.

    > 2.) Does anyone know of a way to script applying this IPSec
    > policy onto other/client PC’s (They’re all Windows XP SP2 boxes).

    You can use netsh to script changes to IPSec. Adding a rule using netsh
    would look something like this.

    netsh ipsec static add filter filterlist="Outbound Filter" srcaddr=me
    dstaddr=any description="HTTP out" protocol TCP srcport=0 dstport=80

    A source port of 0 maps to any.

    See this article in Technet for a more complete reference of netsh.
    http://tinyurl.com/amku6

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Thor (Hammer of God): "Re: Scripted IPSec policies on Windows XP (without AD/GPOs)"

    Relevant Pages

    • Re: IpSEC in Windows an Unix system
      ... create an ipsec policy for Windows 2000/XP Pro/W2003 domain computers via ... Windows comes with three default configured ipsec policies ... ipsec security associations with Windows 2000 computers and the mmc Ipsec ...
      (microsoft.public.win2000.security)
    • Re: Scripted IPSec policies on Windows XP (without AD/GPOs)
      ... ipsec policy configuration tool that will run on both XP and Win2k3. ... technet piece by Steve Riley provides a more detailed overview of the IPSec ... Scripted IPSec policies on Windows XP ... it seems netsh ipsec commands are only supported ...
      (Focus-Microsoft)
    • Re: IPsec tunnel from the commandline
      ... as I know this can only be scripted for Windows 2003 with netsh. ... > Can someone please help me by showing me how to create an IPSec tunnel ... The servers are at different ...
      (microsoft.public.security)
    • Netsh and IPSec Policies
      ... I hope someone can help me with this, I am trying to use 'netsh' on Windows ... 2003 to script the creation of IPSec Policies and IPSec Filters. ... create the Policy as part of the Domain Security Policy it does not work.... ... This command is accepted OK, but then when the follow command runs it fails: ...
      (microsoft.public.windows.server.security)
    • Userrights for VPN IPSec connection ?
      ... clients to connect to company headquarter. ... IP address and via script an local IPSec IP Security ... in in Windows with Administrator rights. ... Main User I can not implement the Security Policy. ...
      (microsoft.public.windowsxp.security_admin)