How does domain isolation with Windows 2003 IPsec happen?



Hi all,

I have a question regarding implementing domain isolation with IPsec
support from Windows 2003 (or higher.)

From the examples online, you only need to join a few machines into
the domain and they are magically protected from outsider attacks and
eavesdropping. I am wondering how exactly this should be configured,
especially using a group policy distributed from the domain
controller.

How should I write this policy in the domain controller? The most
naive way is to list all the IP addresses of all the domain members in
a filter list, and apply "secure" action to this filter. My questions
is, what if a new computer joins the domain or someone left? Do I,
presumably the domain admin, need to reconfigure the filter list every
time?

Is there a better way of doing this? Or, can some one show me the
correct way of doing it?
Thanks a lot!

-Simon
.



Relevant Pages

  • RE: Internet Connection Wizard failing at Firewall Config and Secu
    ... You can use the Dcdiag.exe (Domain Controller Diagnostic Tool) included ... in Windows Support Tools to verify the AD status. ... Windows Server 2003 Active Directory Diagnostics, ...
    (microsoft.public.windows.server.sbs)
  • Re: Event ID: 5719
    ... Windows cannot determine the user or computer name. ... see Help and Support Center at ... This computer was not able to set up a secure session with a domain ... ADDITIONAL INFO If this computer is a domain controller for the ...
    (microsoft.public.windows.server.active_directory)
  • Event ID: 5719
    ... Windows cannot determine the user or computer name. ... see Help and Support Center at ... This computer was not able to set up a secure session with a domain ... If this computer is a domain controller for the specified domain, ...
    (microsoft.public.windows.server.active_directory)
  • How does domain isolation with Windows 2003 IPsec happen?
    ... support from Windows 2003 ... the domain and they are magically protected from outsider attacks and ... How should I write this policy in the domain controller? ...
    (microsoft.public.windows.server.security)
  • Re: AD sites and services
    ... A search for "Active Directory Sites" yeilds the following: ... After an Unsuccessful Domain Controller Demotion" ... http://support.microsoft.com?kbid=220140 "FRS Replication Protocol and Topology ... Windows 2000 Domain Controllers" ...
    (microsoft.public.win2000.active_directory)