IPSec Packet-Filtering Questions

From: Jim C. (tjnaz2001@yahoo.com)
Date: 08/31/02


From: "Jim C." <tjnaz2001@yahoo.com>
Date: Fri, 30 Aug 2002 21:04:34 -0700


Hello,

I am working on an IPSec policy for my web hosting
environment. For the most part, it allows what it is
supposed to and blocks what it is supposed to. However, I
have hit 2 snags.

First, if I log onto the server that has this policy in
place it takes approximately 15 minutes to "load personal
settings". It does this whether I am logging in locally or
using Terminal Services (admin mode). What port(s) and type
(s) does this use? If I stop the IPSec service I get in as
soon as the service stops. I have no issues if the service
is stopped.

Second, if I use the ISM MMC I cannot connect this server
to it. Any idea on which port(s) and type(s) this requires?

I have everything else locked down nicely and it works
with these 2 exceptions.

I do appreciate any help that can be provided.



Relevant Pages

  • Re: More Secured
    ... If you can give the users anonymous access then use FTP, ... passwords will go over the network in plain text to the ftp server. ... The ipsec policy could be configured on ...
    (microsoft.public.win2000.security)
  • Re: Accessing Standalone Wink3 Server from XP Workstations
    ... --Applied IPSec policy on the local Win2k server first by creating an ip ... --There is a seperate standalone sub-CA server which issues certificates. ... Do we really need to implement IPSec policy at the client level as well ...
    (microsoft.public.access.security)
  • Re: IPSec filter to allow only sending e-mail
    ... that the filter is not getting applied after a server restart. ... delivered via a Local IPSec Policy or an IPSec Policy stored in the AD? ...
    (microsoft.public.win2000.security)
  • Accessing Standalone Wink3 Server from XP Workstations
    ... --Applied IPSec policy on the local Win2k server first by creating an ip ... --There is a seperate standalone sub-CA server which issues certificates. ... Do we really need to implement IPSec policy at the client level as well ...
    (microsoft.public.access.security)
  • Re: Multiple IPSec Policies
    ... You can have only one ipsec policy assigned at a time, ... server in the filter list. ... > it talk to 2 servers on speciic ports, it works fine with one sever ... the first policy for the first server gets ...
    (microsoft.public.win2000.security)