Re: IPSec Tunnel vs Transport mode vs Filter



In article <OcZ#QX#PHHA.4372@xxxxxxxxxxxxxxxxxxxx>, MarlonBrown@xxxxxxxxxxxxxxxxxxxxxxxxx
says...
I've seen articles which state that IPSec modes are Tunnel and Transport.

Imagine you create an IPSec filter to protect a web server and you apply
that to the server.

Which classification of IPSec 'mode' is that for that specific scenario? To
my view that is neither Tunnel nor Transport, but correct me if I am wrong.



It is actually a form of IPSec transport mode. You state in the IPSec policy that you will
'block' rather than negotiate connections to any ports other the TCP 80 or TCP 443 and that
no IPSEc action will take place for connections from anyone to your TCP 80 / TCP 443.
Brian
.



Relevant Pages

  • Re: VPN vs SSL client side certificates
    ... I've been asked to setup a web server for a site with security ... >>One suggestion was to setup a VPN (which I'm reading to mean some IPSEC ...
    (comp.security.misc)
  • Re: WebServer behind firewall
    ... The one in front of the web server could be configured to allow only ... You could use ipsec to protect ... The link below goes into much more detail on possible firewall ... > internal network but prevent and secure our network from the outside. ...
    (microsoft.public.windows.server.networking)
  • Re: WebServer behind firewall
    ... The one in front of the web server could be configured to allow only ... You could use ipsec to protect ... The link below goes into much more detail on possible firewall ... > internal network but prevent and secure our network from the outside. ...
    (microsoft.public.windows.server.security)
  • IPSec Tunnel vs Transport mode vs Filter
    ... I've seen articles which state that IPSec modes are Tunnel and Transport. ... Imagine you create an IPSec filter to protect a web server and you apply ...
    (microsoft.public.security)
  • Re: encrypt server data
    ... I guess you need to set 'vpn' for the sql and web server. ... > to a SQL server that is on the internal LAN behind a firewall. ... > that NAT and Ipsec have problems coexisting. ...
    (microsoft.public.inetserver.iis.security)