Re: authentication problem

From: Andrew Mitchell (amitchel_at_removecasey.vic.gov.au)
Date: 03/17/04


Date: Wed, 17 Mar 2004 03:59:01 -0800


"Steven L Umbach" <sumbach@N0spam.ameritech.net> said

> I have tried a number of various policy configurations in the past
> with regards to ipsec negotiation between domain members and domain
> controllers. I could never get it to work without a problem. Microsoft
> officially does not support ipsec negotiation communications between
> domain members and domain controllers for either W2K or Windows 2003.
> The only way I get it to work is to exempt all traffic between domain
> controllers and doman members which is not explained in very much
> documentation. See the links blow for more info. --- Steve
>
> http://support.microsoft.com/?kbid=254949

Steven,
I think you may have misread the content of the above article.
It is referring to traffic between domain controllers and *non* domain
members, not between DC's and members of the domain. If the client is not a
member of the domain it cannot retreive the IPSec policy from the DC, the
same way it will not get any other group policies. Domain members have no
such problem.
What problems have you been experiencing?

Regards
Andy.



Relevant Pages