Re: Ipsec

From: Kerodo (loopback_at_localhost.com)
Date: 01/28/05


Date: Thu, 27 Jan 2005 16:30:53 -0800

In article <Xns95EBB9D5A66A0notmenotmecom@204.127.199.17>,
notme@notme.com says...
> Kerodo <loopback@localhost.com> wrote in news:MPG.1c62d145a5f7493c989680
> @news.west.cox.net:
>
> > I just discovered IPSEC on my Win2k system. What a great find! I have
> > it set up as a basic packet filter now, allowing what ports and
> > addresses I need outbound, and blocking everything inbound. No need for
> > a 3rd party firewall anymore. No app control, but who cares? I don't
> > need it anyway.
> >
> > Question: I don't suppose there's any way to get some kind of logging
> > out of IPSEC is there? I don't really need it I guess since I've seen
> > what typical stuff comes in here with all my other firewalls, but I'm
> > just curious if it's possible... I don't see any way to do it so far..
> >
>
> IPsec is cool but it's a pain in the ass with the high ports when a high
> port is used for a download. You either have to create rules or drop IPsec.
> If you're behind an appliance or PFW, then that's no big deal with dropping
> IPsec. It also interfered with the logging from the router where I had to
> set rules to let the logging in on the port that the logging application
> running on the machine needed open - just a little FYI.
>
> If you don't know about the AnalogX file, then take a look at the rules (a
> good way to learn rules and protocols) that are made for HTTP, POP3, NNTP,
> etc and you can implement the AnalogX file on Win 2k, XP and Win 2K3 O/S.
>
> http://tinyurl.com/1mls
>
> It has logging but I never used it and it may or may not be what you're
> looking for.
>
> http://tinyurl.com/46fft
>
> I used IPsec to supplement BlackIce on the outbound and BlackIce did report
> on the activies of IPsec when Ipsec was doing the blocking.
>
> Duane :)
>

Thanks very much for the links Duane. I'll read them now..

-- 
Kerodo


Relevant Pages

  • Re: I am sick of windows firewall
    ... the XP FW if you need to stop outbound packets. ... I have made my adjustments to IPsec to supplement BlackIce ... the Windows networking ports even though BI was stopping ...
    (comp.security.firewalls)
  • Re: I am sick of windows firewall
    ... I use the AnalogX IPsec rules to supplement BlackIce ... need IPsec to stop outbound that BlackIce cannot do by ... attempts on the Windows networking ports even though BI ...
    (comp.security.firewalls)
  • Re: I am sick of windows firewall
    ... the XP FW if you need to stop outbound packets. ... I have made my adjustments to IPsec to supplement BlackIce ... the Windows networking ports even though BI was stopping ...
    (comp.security.firewalls)
  • Re: Ipsec
    ... and blocking everything inbound. ... IPsec is cool but it's a pain in the ass with the high ports when a high ... It also interfered with the logging from the router where I had to ...
    (comp.security.firewalls)
  • Re: Windows Explorer eludes firewall
    ... What kind of firewall are you using and how do you configure the logging? ... ports 80 and 443 outbound if you are not already. ...
    (microsoft.public.win2000.security)