RE: Setting up IPSEC with servers in and out of a domain



Marty,

That is doable.
The conditions are that you will have to open the IPSEC ports on FWs on both
side of the communication channel.

IKE on UDP 500, IP 50 or IP 51 depending on either you are using AH or ESP
on the FWs at each side of the communication link.

If both servers are behind NAT devices the only ports you'll need will be
UDP 500 (IKE, ISAKMP) and UDP 4500 for NAT Traversal.

Be aware that Cisco IPSEC implementation will require an additional port to
be open; I think it is TCP 10000.

Cheers,
Serge Vondandamo, HND, CCNA, CISSP

-----Message d'origine-----
De : listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] De
la part de Marty
Envoyé : lundi 19 novembre 2007 19:11
À : focus-ms@xxxxxxxxxxxxxxxxx
Objet : Setting up IPSEC with servers in and out of a domain

Greetings list,

Has anyone had success with using IPSEC to encrypt traffic between a
server in a domain and a server not in a domain? If not, are there
any third party solutions out there that can do this?

Thanks in advance,
Marty



Relevant Pages

  • Re: Windows 2003 Server RRAS and IPSEC
    ... You can check out the following link for info regarding the ports to be ... parallel firewalls or utilize filters like IPSEC to protect our servers (we ... 443, our campus DNS servers, and campus time servers. ... our campus dialup service then dialed the vpn connection to the new RRAS ...
    (microsoft.public.win2000.ras_routing)
  • Re: IPSEC and IP Filtering Both Prevent Internet Browsing
    ... ports exempt to ipsec traffic. ... For udp traffic, all I ever had to do was create a mirrored outbound rule to ... The internet is also plastered ...
    (microsoft.public.win2000.security)
  • Re: IIS IpSec
    ... >> 5.0 Server in Windows 2000 Server. ... >> I am using IPSec and it's working good, ... >> open the FTP ports 20-21 and HTTP port 80 for the TCP ... >> for UDP, but my websites don't come up now. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Firewall between DC and Member Server
    ... Steve's article actually lists all the protocols required between AD client ... We have decided not to use IPsec to deploy AD in our multiDMZ environment. ... > traffic - or limit RPC to known ports as well as the AD ports. ... >> member servers at another. ...
    (microsoft.public.security)
  • Re: Slow Logon Issue
    ... It was not a port issue rather kerberos was ... What ports did you open on the firewall? ... controller using the UDP network protocol.This is typically due to ... "There are currently no logon servers available to service the logon ...
    (microsoft.public.windows.server.active_directory)