Re: IPSEC

From: David Beder [MSFT] (dbeder_at_online.microsoft.com)
Date: 10/05/04


Date: Tue, 5 Oct 2004 00:28:11 -0700

netdiag doesn't have ipsec support in ws03. on the newer platform you need
to use the dynamic ipsec context of the command-line netsh (netsh ipsec
dynamic) shell, or the ipsec monitor mmc snap-in.

I will try and track down the current owner of this kb and have the content
updated. I'm feeling a bit blind but I still can't find where it tells you
to create a policy on the cisco server so I'll try and get that noted as
well.

Please post back with the ip addresses of the interfaces you've got as well
as what each filter on each box looks like and we'll see where the config is
off. If you're not putting this together using a pre-shared key, what auth
menthod have you chosen?

-- 
David
Microsoft Windows Networking
This posting is provided "AS IS" with no warranties, and confers no rights.
"David" <nzamoeba@neinspamhotmail.com> wrote in message 
news:452d01c4a070$ea7c1c00$a301280a@phx.gbl...
> Hope this is the best forum to ask...
>
> http://support.microsoft.com/default.aspx?scid=kb;en-
> us;816514&Product=winsvr2003
>
> I'm a student trying to implement IPSEC on a makeshift
> network running windows 2003. I've been using the above
> knowledge base article (816514) and have followed the
> instructions to the letter, its been quite accurate and
> helpfull.
>
> However, when it comes to the section where I run netdiag
> to test that it is running, netdiag always skips the ip
> security test, even when I specify it. This typically
> means that IPSEC has not been implemented. However, IPSEC
> says it is running on the services window.
>
> So what could be causing this? why does one thing say
> ipsec is running, while the other says its not? Before I
> started this I had full pinging over my mini-routed
> network, now I have none.
>
> Breif picture of my network: its just 4 pc's, and one
> cisco router, 2 pc's to a domain. (2 domains)
>
> On one domain I have win2k3 running as a DC, DNS, and
> router, as well as an xp client. The other domain has a
> DC with DNS but no routing, instead there is another
> win2k3 box acting as a router only. Between these two
> domains sits my cisco router.
>
> XP -- DC(w/ routing) -- Cisco -- win2k3 router -- DC
>
> Any ideas? I've been VERY carefull to follow every
> instruction in the KB article. 


Relevant Pages

  • IPSEC
    ... I'm a student trying to implement IPSEC on a makeshift ... network running windows 2003. ... cisco router, ...
    (microsoft.public.security)
  • Re: W2K domain IPsec implementation
    ... the user is not a local administrator. ... Try using netdiag also when logged on ... if the ipsec policy is active. ...
    (microsoft.public.windows.server.security)
  • Re: IPSEC
    ... security associations and statistics. ... Netdiag can also be used to view ipsec policy ... > I have secured one of my member servers to require IPSEC ... I used group policy to do this. ...
    (microsoft.public.win2000.security)
  • Re: Green Admin - Brute Force Attack - Pls Help
    ... Ipsec configuration is very similar [if ... specifics on how to use ipsec "filtering" policy to protect computers. ... is managing a network - particularly one in a hostile environment. ...
    (microsoft.public.security)
  • Re: Malicious Software Removal Tool Errors Reported
    ... chkdsk while the errors are occuring resolves the problem. ... don't know if the IPsec service is running or not. ... IPSec Services: IPSec Services failed to get the complete list of network ...
    (microsoft.public.windowsxp.general)

Quantcast