Re: IPsecpol and DNS lookup question
From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 12/18/02
- Next message: mariuszgib: "Re: w32com.exe"
- Previous message: Karl Levinson [x y] mvp: "Re: virus? hacked?"
- In reply to: Steve Riley \(MSFT\): "Re: IPsecpol and DNS lookup question"
- Next in thread: Jane Tunnicliff: "Re: IPsecpol and DNS lookup question"
- Reply: Jane Tunnicliff: "Re: IPsecpol and DNS lookup question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Karl Levinson [x y] mvp" <levinson_k@excite.com> Date: Wed, 18 Dec 2002 09:27:44 -0500
... by allowing traffic to UDP and TCP ports 53 on the DNS server, in case
you needed to know.
"Steve Riley (MSFT)" <steriley@microsoft.com> wrote in message
news:eh9gM3lpCHA.1612@TK2MSFTNGP09...
> I presume you mean DNS *name* when you say "DNS address."
>
> Remember that the computer will have to perform a DNS lookup if you use
DNS
> names in IPSec filter lists. Make sure that your policy is allowing access
> to your DNS servers so that name resolution can occur.
>
> --
> --------------------------------
> Steve Riley
> MCS Security Consulting Practice
> steriley@microsoft.com
> --------------------------------
>
>
> "Jane Tunnicliff" <jtunn@uwpn.org> wrote in message
> news:e06gzCgpCHA.2444@TK2MSFTNGP10...
> > I have been using the Win 2 K command line IPSec tool, IPsecpol.exe. I
> > have a filter that is configured to allow traffic to and from a
particular
> > DNS address. I can ping the DNS address successfully (it is a group of
> > multiple time servers). If I set the filter to allow traffic to and
from
> > the DNS address it fails.
> > If I set the filter to allow traffic to and from a specific IP address
> > (within that DNS group), then the filter works just fine.
> >
> > We are not running Active Directory DNS within our domain. Does anyone
> know
> > if IPSecpol filters, in static mode, can be configured to use a DNS
> address
> > instead of an IP address?
> >
> > Thanks for any information.
> >
> >
>
>
- Next message: mariuszgib: "Re: w32com.exe"
- Previous message: Karl Levinson [x y] mvp: "Re: virus? hacked?"
- In reply to: Steve Riley \(MSFT\): "Re: IPsecpol and DNS lookup question"
- Next in thread: Jane Tunnicliff: "Re: IPsecpol and DNS lookup question"
- Reply: Jane Tunnicliff: "Re: IPsecpol and DNS lookup question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|