Re: Microsoft IPSec via group policy



Hi Jesse,

Answers are below ...

----- Original Message -----
From: "Jesse Rink" <jesse-rink@xxxxxxxxx>
To: "'Paul J. Brickett'" <swarzkopf@xxxxxxxxxxxxxxxxxx>
Cc: <security-basics@xxxxxxxxxxxxxxxxx>; <security-basics-return-47647@xxxxxxxxxxxxxxxxx>
Sent: Wednesday, February 06, 2008 12:03 PM
Subject: RE: Microsoft IPSec via group policy


Hello.
Sorry for the delayed response. For some reason when I post on this list,
my posts sometimes don't' show up for 16-30 hours. Not quite sure why.

What I'm attempting is to encrypt network traffic between my clients and my
domain controllers and clients and my member servers.

I have tried setting IPSec up in group policy however I'm running into some
strange issues. What I've done to set this up for testing is this...

1. In the Domain Controllers OU and GPO, I set the IP Sec policy for Server
(request security) - Assigned.

Your Domain Controllers should not receive any IPSEC Policy, in fact they must run in clear. I suggest to you create all IPSEC GPO's on root domain and made filters based on ACL


2. In the test PC OU and GPO, I set the IP Sec policy for Client (respond
only) - Assigned.

At this time, I think I should be good to go. I go to the XP client and do
a gpupdate /force and reboot the computer. Now, here's what's odd.
According to documentation I've read, I should be able to tell the IP Sec
policy applied to the client in the following ways:

1. I should be able to do an RSOP.msc from Start|Run on the XP client and
see the IP Sec policy. I try that, but nothing shows up.

You can see by IPSec Monitor.

2. I should be able to look at the Local Security Policy on the XP client
and it should show that IP Sec policy has been applied from a GPO. I try
that, but nothing shows up.

I am starting to wonder if the documentation I've read is WRONG about these
things. I have noticed this... If I look on the XP Client's registry, under
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPsec\GPTIPSECPolicy and under
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPsec\Policy\Cache, I "DO" find
that these keys are created/updated after doing the gpupdate /force and
rebooting, so it SEEMS like IPSec is getting applied? But again, RSOP.msc
and the Local Security Policy show NOTHING. Why is this?

Also, I am testing what happens if the IPSec policy on the client is
unapplied. This is very strange as well. If after having applied the IP
Sec policy via GPO to the XP Client, I remove it a short time later by going
into the GPO for the PC OU, and changing Client (respond only) to Unassign,
when I then go to the XP client and do a gpupdate /force and then reboot,
the XP client can no longer contact the domain controller. I can't even
ping it, nor can the domain controller ping the client. This doesn't make
sense. I am removing the IP Sec policy from the client "by the book" as far
as I can tell by unassigning it first, and then making sure the new GPO is
applied to the PC. Any idea on this particular issue?

Like you said before, your Domain Controller are set to request IPSec for communication, in this profile you cannot talk with your server without IPSec.


I'm about ready to open up a case with Microsoft to figure this stuff out.
Thanks for any help.


May I Suggest you two articles that I wrote about Ipsec, perhaps this information can help you.

http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=49593

http://www.microsoft.com/technet/community/columns/secmvp/sv0906.mspx



JR



-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] On
Behalf Of Paul J. Brickett
Sent: Tuesday, February 05, 2008 11:02 AM
To: jesse-rink@xxxxxxxxx
Cc: security-basics@xxxxxxxxxxxxxxxxx;
security-basics-return-47647@xxxxxxxxxxxxxxxxx
Subject: Re: Microsoft IPSec via group policy

What exactly are you trying to do? Providing detail to the group may
elicit more responses.

I've deployed several IPSec GPOs- I generally have used IPSec GPOs to more
granularly block/allow access to specific ports/protocols. I find that
it's a more precise tool then Windows Firewall. I often find myself
comparing it to IPTables.

-PJB

On Mon, 4 Feb 2008, jesse-rink@xxxxxxxxx wrote:

Just curious if anyone on the list has implemented IPsec for Windows
2003/XP via Group Policy? I am testing this out and finding some strange
results that I'd like to bounce off someone who's done this before.
Anyone?

JR

--------------------------------------------------------------------
mail2web.com - Enhanced email for the mobile individual based on
MicrosoftR
Exchange - http://link.mail2web.com/Personal/EnhancedEmail









Relevant Pages

  • re: Microsoft IPSec
    ... My original intention for enabling IPsec was the prevent users from ... Microsoft IPSec via group policy ... Requiring ipsec between a client and a DC via GPO is problematic. ...
    (Security-Basics)
  • RE: Microsoft IPSec via group policy
    ... IPsec could accomplish this. ... Microsoft IPSec via group policy ... Requiring ipsec between a client and a DC via GPO is problematic. ...
    (Security-Basics)
  • RE: Microsoft IPSec via group policy
    ... IPsec could accomplish this. ... Microsoft IPSec via group policy ... Requiring ipsec between a client and a DC via GPO is problematic. ...
    (Security-Basics)
  • IPSec and Group Policy
    ... I am trying to use Group Policy to apply IPSec policy to an Organizational ... W2k domain, as the local administrator, and set the Local Security Policy to ...
    (microsoft.public.win2000.security)
  • Re: Configured IPSec Policy is not working.
    ... As for the RRAS filters themselves, they're fairly basic, requiring ipsec ... and encryption will depend on the security settings of the connection. ... why exactly do you want to use l2tp without any ipsec protection rather ... > What is the default filter rule and filter policy ...
    (microsoft.public.win2000.ras_routing)