Re: IPsecpol and DNS lookup question

From: Jane Tunnicliff (jtunn@uwpn.org)
Date: 12/18/02


From: "Jane Tunnicliff" <jtunn@uwpn.org>
Date: Wed, 18 Dec 2002 08:46:20 -0800

Thanks for the replies...

To clarify - I already have an IPSec filter that allows traffic to and from
our DNS servers. DNS resolution is working fine.

I am attempting to add another filter (to a Network Time Protocol server).
The filter works if I set the destination address to an IP address (one of
several NTP server addresses). The filter fails if I set the destination
address to a DNS name. I can see in the GUI, that there is a place to add
a destination DNS name, but I can't figure out how to access that with the
command line tool.

The following line works fine
ipsecpol -x -w REG -p "IISFilters" -r "NtpOK" -n PASS -f
0+140.142.33.3:123:UDP
I would prefer to have the NTP lookup go to the DNS name (which is a farm of
NTP servers) instead of directing the filter to a single NTP server IP
address.

I can't get this filter to work-
 ipsecpol -x -w REG -p "IISFilters" -r "NtpOK" -n PASS -f
0+time.u.washington.edu:123:UDP

I have read all of the syntax in the IPSec .html help document. It seems to
indicate that in static mode a DNS name will resolve to multipe addresses.
I am not sure if I have a syntax error, or if this feature just doesn't
work.

Thanks for any advice.

"Karl Levinson [x y] mvp" <levinson_k@excite.com> wrote in message
news:u0JroHqpCHA.2772@TK2MSFTNGP09...
> ... by allowing traffic to UDP and TCP ports 53 on the DNS server, in case
> you needed to know.
>
>
> "Steve Riley (MSFT)" <steriley@microsoft.com> wrote in message
> news:eh9gM3lpCHA.1612@TK2MSFTNGP09...
> > I presume you mean DNS *name* when you say "DNS address."To
> >
> > Remember that the computer will have to perform a DNS lookup if you use
> DNS
> > names in IPSec filter lists. Make sure that your policy is allowing
access
> > to your DNS servers so that name resolution can occur.
> >
> > --
> > --------------------------------
> > Steve Riley
> > MCS Security Consulting Practice
> > steriley@microsoft.com
> > --------------------------------
> >
> >
> > "Jane Tunnicliff" <jtunn@uwpn.org> wrote in message
> > news:e06gzCgpCHA.2444@TK2MSFTNGP10...
> > > I have been using the Win 2 K command line IPSec tool, IPsecpol.exe.
I
> > > have a filter that is configured to allow traffic to and from a
> particular
> > > DNS address. I can ping the DNS address successfully (it is a group
of
> > > multiple time servers). If I set the filter to allow traffic to and
> from
> > > the DNS address it fails.
> > > If I set the filter to allow traffic to and from a specific IP address
> > > (within that DNS group), then the filter works just fine.
> > >
> > > We are not running Active Directory DNS within our domain. Does
anyone
> > know
> > > if IPSecpol filters, in static mode, can be configured to use a DNS
> > address
> > > instead of an IP address?
> > >
> > > Thanks for any information.
> > >
> > >
> >
> >
>
>



Relevant Pages

  • Re: Spam solutions - written smtp sink or spam software?
    ... that his client has a messed up DNS record and that's why you rejected it. ... I think you will find that the quality anti spam solutions out there work ... MVP - Exchange ... >I am looking for a spam filter. ...
    (microsoft.public.exchange.admin)
  • Update
    ... I rebooted my ISA server and DNS lookups started to pass via ISA even ... > Do I need to have enabled the DNS filter that comes with default ISA ...
    (microsoft.public.isa)
  • Re: Help With DNS Through VPN
    ... the pre-defined DNS lookup filter is used to allow DNS queries FROM ... You need to allow DNS queries TO ISA - not the ... your DNS server on the ISA2000 machine, see this excellent article by Tom ...
    (microsoft.public.isa)
  • Re: SMTP Woes
    ... You might want to look at the Exchange Intelligent Message Filter first, ... One often neglected area is to take a look at who is hitting your DNS ... send 10's or 100's of requests a day to your DNS server? ... to anyone except your ISP). ...
    (microsoft.public.exchange.admin)
  • Re: SMTP Woes
    ... You might want to look at the Exchange Intelligent Message Filter first, ... One often neglected area is to take a look at who is hitting your DNS ... send 10's or 100's of requests a day to your DNS server? ... to anyone except your ISP). ...
    (microsoft.public.isaserver)