Re: IPSEC Between two PCs in Win2K

From: Steven L Umbach (sumbach55_at_ameritech.net)
Date: 11/28/03


Date: Fri, 28 Nov 2003 05:31:18 GMT

I assume you did that on both computers. I have found ping a somewhat
unreliable method at times of proving ipsec connectivity as it seems that
ping may time out before SA is established. I would double check that ipsec
policy is indeed assigned to each computer. You could try somehing like
accessing a share and transfering a file and then using ipsecmon to see if
ipsec encryption is being used. Netdiag is helpful in determining what ipsec
policy if any is assigned to a computer. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q321708
http://www.brienposey.com/kb/monitoring_secured_communications_through_ipsecmon.asp

<anonymous@discussions.microsoft.com> wrote in message
news:001c01c3b55e$72bdf1f0$a001280a@phx.gbl...
>
> >Make sure that you are using
> >the same pre shared keys for authentication and
> >that your policy allows ICMP.
>
> I just followed the steps in the article: one of the steps
> required me to enter the "123456789" as a pre-shared key
> on both PCs. Another step required me to choose "All IP
> Traffic" as an IP Filter. That's what I've done for both
> of these steps. As I said, I have repeated all steps in
> article several times with the same negative result.
>
> Thanks for your reply.
>
> Eugene.
>
> >-----Original Message-----
> >Make sure that you are using the same pre shared keys for
> authentication and
> >that your policy allows ICMP. --- Steve
> >
> >http://support.microsoft.com/default.aspx?scid=kb;en-
> us;257225
> >
> >"EugeneN" <anonymous@discussions.microsoft.com> wrote in
> message
> >news:029501c3b522$69f5fc70$a101280a@phx.gbl...
> >> Hi,
> >>
> >> For IPSEC testing purposes I am trying to setup an IPSEC
> >> chanel between two PCs with Win2K Prof (workstations). I
> >> am strictly following the porocedure outlined in the MS
> >> Article "Step-by-Step Guide to Internet Protocol
> Security
> >> (IPSec)"
> >>
> (www.microsoft.com/windows2000/techinfo/planning/security/i
> >> psecsteps.asp).
> >>
> >> All steps are giving me the expected results on both
> >> computer except the one when I am trying to "ping" the
> >> another computer's IP Address. First time I ping, I am
> >> getting the expected results of "Negotiating IP
> Security."
> >> message. But then regardless of the number of time I
> ping,
> >> I am still getting the same "Negotiating IP Security."
> >> messages, and no ping echo reply.
> >>
> >> I repeated the procedure multiple times from scratch
> with
> >> the same outcome. I verified that IPSEC Policy Agent is
> >> running on both PCs. I hooked up the network sniffer and
> >> made sure that ISAKMP messages are being exchanged
> between
> >> two PCs. But still no further IPSEC packets can be seen.
> >>
> >> Is there anybody who would do that successfuly ? Are
> there
> >> any "gotchas" I should be aware of when setting the
> IPSEC
> >> between two PCs ?
> >>
> >> Thanks,
> >>
> >> Eugene.
> >>
> >>
> >
> >
> >.
> >



Relevant Pages

  • Re: IPSEC Failing (Secure Server)
    ... Troubleshooting IPSec ... exchanges by enabling Audit Policy, which causes security events to be ... logged in the security log of the Event Viewer. ... Networking, Internet, Routing, VPN, Anti-Virus, Tips & Troubleshooting on ...
    (microsoft.public.windows.server.networking)
  • Re: OU Security - best setup?
    ... configure the Domain Security Policy to use password complexity as poor passwords are ... Pro computers however can use ipsec and domain controllers must be exempt from ipsec ... > restrict what users can ...
    (microsoft.public.win2000.security)
  • RE: Access to well-known ports on Win2K
    ... IPSEc does not provide security at the user level; ... policy - works for all users of the machine; and can allow or block access ... many routes for deployment as you mention: Group Policy; Local Security ... > TCP/IP Filtering does not provide port level security at the ...
    (Focus-Microsoft)
  • Re: Windows 9x clients authentication
    ... configuring the lan manger authentication level to be "send ntlmv2 responses ... That is a security option under security settings/local ... The only really secure method would be to use ipsec "require" policy on all ...
    (microsoft.public.win2000.security)
  • Re: Cant ping my XP Pro laptop
    ... You'll see a node for "IP security" policy, make sure no IPSec ... > Look in Properties for TCP/IP, Advanced, Options, IP Security, Properties. ...
    (microsoft.public.windowsxp.security_admin)