Re: isakmp

From: Valdis.Kletnieks@vt.edu
Date: 08/02/01


Message-Id: <200108021921.f72JLvw26541@foo-bar-baz.cc.vt.edu>
To: baudendist@primary.net
Subject: Re: isakmp 
From: Valdis.Kletnieks@vt.edu
Date: Thu, 02 Aug 2001 15:21:57 -0400

On Thu, 02 Aug 2001 13:46:32 CDT, baudendist@primary.net said:
> Yea... We were watching this yesterday... It looks like the packets are
> coming from WIN2K IPSec enabled web servers... It goes back to the 19th...
> VPN??? WIN2K interaction with the worm? Incidental? Who knows????

Isn't there a configure tab in the TCP control panel that has a checkbox
to force it to always try to negotiate IPSec first? Could it just be
CodeRed running on a box that has this set?

-- 
				Valdis Kletnieks
				Operating Systems Analyst
				Virginia Tech




Relevant Pages

  • Re: Expectation from VPN (sbs2003premSp1)
    ... A connection between the VPN server and the VPN client 222.152.16.132 has ... your VPN server and the Internet allow GRE packets. ...
    (microsoft.public.windows.server.sbs)
  • Re: Expectation from VPN (sbs2003premSp1)
    ... That the Alcatel 530 router ... > A connection between the VPN server and the VPN client 222.152.16.132 has ... > your VPN server and the Internet allow GRE packets. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN over wireless
    ... The RSA key is for authentication, ... Only the payload data packets are encrypted. ... The key exchange mechanism varies with the type of encryption. ... With a VPN, only the packets going between the VPN client and VPN ...
    (alt.internet.wireless)
  • Re: DCPROMO RPC error
    ... Over the weekend I was involved in Joining a Windows 2003 server in the US to our domain here in Sydney over an IPSEC VPN. ... Kerberos uses connectionless UDP datagram packets. ... Depending on the virtual private network hardware configuration, these larger packets have to be fragmented when going through a VPN. ... Because UDP is a connectionless protocol, fragmented UDP packets will be dropped if they arrive at the destination out of order.If you change MaxPacketSize to a value of 1, you force the client to use TCP to send Kerberos traffic through the VPN tunnel. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DCPROMO RPC error
    ... Promote a Domain Controller over an IPSEC VPN - Kerberos over tcp - ... Kerberos uses connectionless UDP datagram packets. ... you change MaxPacketSize to a value of 1, you force the client to use TCP ...
    (microsoft.public.windows.server.active_directory)

Quantcast