Re: Setting up IPSec on a webserver

From: x y (jamescagney90210@excite.com)
Date: 06/16/02


From: "x y" <jamescagney90210@excite.com>
Date: Sat, 15 Jun 2002 19:00:32 -0400


IPsec in windows 2000 has I believe two main functions: deciding when to
encrypt network traffic and deciding when to filter or block network
traffic. Using packet filters to block certain ports on a web server can be
a good idea to secure it, though I wouldn't recommend using win2000 ipsec
port filtering as there is no logging, which is essential IMHO. You could
consider using sygate firewall which is free for non-commercial use and
around $35 for business use. even though it may feel funny putting free
software that is most commonly used for workstations, the vendor claims it
is also suitable for servers.

enabling encryption of traffic on a web server between it and other windows
2000 servers on your internal network [such as a domain controller for
authentication, sql server, etc] might not be a bad idea depending on your
needs, if you are concerned about a hacker hacking one of the systems on
your internal network and installing a sniffer to capture and read the
traffic.

"tc" <tcruise@ev1.net> wrote in message
news:e77501c212f5$c962d460$39ef2ecf@TKMSFTNGXA08...
> What do I gain in terms of security from setting up IPSec?
>
> How do I setup and configure IPSec for my webserver?



Relevant Pages

  • Re: March 29, 2006 total eclipse - IT admins WORST NIGHTMARE
    ... and NewsProxy is the answer for that. ... > Comcast news server. ... simply filters out what I dont want on the network. ... NewsProxy - Network level killfile and content filter for Usenet. ...
    (comp.security.firewalls)
  • Re: IPSec / domain isolation: confusing MS documents
    ... workstation, he is able to attach to server ressources again, but for our ... The user right for access this computer from the network ... will not work for computer accounts unless ipsec is being used. ... securing a domain controller. ...
    (microsoft.public.windows.server.security)
  • Re: Packet filter just wont work.
    ... You use packet filters to provide access to the ISA Server itself, ... DMZ network. ... delete the packet filter and try creating a Server Publishing rule ...
    (microsoft.public.isa.configuration)
  • Re: GPO, IPSec and network utilization
    ... If you deploy IPSec, consider using Network cards that support IPSec offload ... > I have read that it can slow network communications somehwat though not> usually drastically. ... W95/98 and NT4.0 computers are not ipsec> capable, so if you have a server with a require policy they will not be able> to communicate with it. ...
    (microsoft.public.win2000.security)
  • Re: Network Infrastructure
    ... AD Server with DNS Server - is this a good practice? ... I want my network to have access limitations. ... wireless using MAC Address filter from the routers. ...
    (microsoft.public.windows.server.active_directory)