IPSEC BUG - Cannot filter - Subnet Mask invalid

From: Steven E. Adams (stevea1@home2offic.com)
Date: 12/06/02


From: "Steven E. Adams" <stevea1@home2offic.com>
Date: Fri, 6 Dec 2002 12:54:45 -0800


I have looked at this article before posting...
Traffic That Can--and Cannot--Be Secured by IPSec (253169)

Using IPSEC, I can not enter these addresses in the "IP
Filter List" to Filter ASIAN Networks:

200.0.0.0 / 255.0.0.0
203.0.0.0 / 255.0.0.0
211.0.0.0 / 255.0.0.0
212.0.0.0 / 255.0.0.0
213.0.0.0 / 255.0.0.0
218.0.0.0 / 255.0.0.0
219.0.0.0 / 255.0.0.0

(I am sure there are more)
I get an error "This is an invalid MASK for the specified
IP Address"

HOWEVER, When I enter in these IP Addresses, I DO NOT get
an error:

61.0.0.0 / 255.0.0.0
80.0.0.0 / 255.0.0.0

Is this a bug in the IPSEC Policy?
Is there a patch?
Am I doing something Wrong?

UNIX & LINUX Firewall rules do this no problem, IPCHAINS,
ETC... It would be great if Microsoft would get the IPSEC
to work they way I would like to use it.

Steven E. Adams



Relevant Pages

  • Re: IPSEC BUG - Cannot filter - Subnet Mask invalid
    ... since IPsec ... > Filter List" to Filter ASIAN Networks: ... > UNIX & LINUX Firewall rules do this no problem, IPCHAINS, ... It would be great if Microsoft would get the IPSEC ...
    (microsoft.public.win2000.security)
  • Re: Setting up IPsec tunnel with 3rd party routers
    ... Posting on MS newsgroup will benefit all readers and you may get more help. ... > I am trying to set up an IPSec tunnel with a 3rd party gateway device ... > such as a Linksys / Netgear VPN router. ... > instructions in the following KB and set up the ipsec policy. ...
    (microsoft.public.windows.server.networking)
  • Re: IPSec Interfaces
    ... is your USB broadband modem the only interface IPSec can't see? ... Microsoft/Windows/Networking/Secure Network Services/IP Security ... This posting is provided "AS IS" with no warranties, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: IPSEC BUG - Cannot filter - Subnet Mask invalid
    ... Just for the hell of it, I tried a 2-octect like you ... better, since IPsec ... >> UNIX & LINUX Firewall rules do this no problem, ... It would be great if Microsoft would get the ...
    (microsoft.public.win2000.security)
  • Re: ip filtering
    ... 813878 How to Block Specific Network Protocols and Ports by Using IPSec ... Diana. ... This posting is provided "AS IS" with no warranties, ...
    (microsoft.public.win2000.security)