Re: IPSec

From: Steven L Umbach (n9rouz_at_nscomcast.net)
Date: 12/05/03


Date: Fri, 05 Dec 2003 02:03:12 GMT

Create one rule that blocks all ip and is mirrored. Then create another rule for your
subnet that permits your subnet address and is mirrored. Then add more specific
exceptions for permitted traffic by protocol/port/address if needed. See link for
good tutorial below. --- Steve

http://www.securityfocus.com/infocus/1559

"Mark" <mchristo@iupui.edu> wrote in message
news:O1oYuIduDHA.640@tk2msftngp13.phx.gbl...
> Starting to test ipsec on my w2k server. I want to permit all computers on
> my subnet, but block all other pc's. How can i do this? I tried to set up
> a policy that blocks all incoming pc's with one filter and permit my subnet
> with another filter. This doesn't work, it blocks everyone. Please help.
>
> Thanks
>
>



Relevant Pages

  • Re: IPSec Filter Question
    ... IPSec filter. ... The first blocks any traffic from a subnet ... I cannot get to 172.16.8.152 no matter what I do from any client ... I just can't figure out why using the more specific filter (PERMIT to only ...
    (microsoft.public.windows.server.networking)
  • Re: cleanning up crazy inside nat list
    ... They also have a permit for the nat subnet in the router's ... Do I need all this deny statements? ...
    (comp.dcom.sys.cisco)
  • Re: Newbie question C837
    ... >> How would I allow the whole subnet through to another subnet? ... If your trying to make an ACL for a single IP you use the word host. ... trying to allow a subnet then you use a wildcard mask. ... In your instance wanting to permit the 192.168.50.0 subnet to talk to the ...
    (comp.dcom.sys.cisco)
  • IPSec Filter Question
    ... I'm working on a server with 2 nics and trying to implement a fairly simple IPSec filter. ... Nic1 faces the network ... The first blocks any traffic from a subnet ... if I change the second filter to PERMIT traffic from the subnet ...
    (microsoft.public.windows.server.networking)
  • cleanning up crazy inside nat list
    ... Most of my router have deny for all the other remote subnets in my ... They also have a permit for the nat subnet in the router's ... Do I need all this deny statements? ...
    (comp.dcom.sys.cisco)