Re: Windows 2000 IPSec Not Blocking Traffic

From: Phil Murnane (pjmurnane_at_yahoo.com)
Date: 09/24/04


Date: 23 Sep 2004 16:58:41 -0700

Steve:

Thanks for the ideas, especially the netdiag one (I'd forgotten about
netdiag entirely). Event Viewer hasn't been reporting anything
unusual. Once I have something to report, I'll post an update.

Thanks Again,
--Phil

> I have never added that many addresses to a rule and don't know if there is a limit
> or not. What you could try is to delete five or so old entries to see if that makes a
> difference and then maybe unassign and then assign the policy again. Another thing to
> try is to create a new identical rule in your policy with a different name to see if
> there is a possible limit that may apply to a rule but not a policy. Also look in
> Event Viewer for any errors and run the netdiag support tool to test ipsec as in "
> netdiag /test:ipsec /debug " to see if it reports a problem.. --- Steve



Relevant Pages

  • Re: Problem with migrating SIDs
    ... Controller Policy as below: ... please check run Dcdiag and Netdiag to ... what migration scenario you are involved in: ...
    (microsoft.public.windows.server.migration)
  • Re: Path Rules - Enabled Paths sometime are restricted
    ... machine I ran netdiag and dcdiag. ... all DC were as expected and DNS records were good. ... the proper policy was applied and came from our ... domain controler named SKIP. ...
    (microsoft.public.windows.group_policy)
  • Re: gp error
    ... netdiag, gpotool, and dcdiag look good. ... that is not receiving the Group Policy are any errors found? ... > PASS - All the DNS entries for DC are registered on DNS server ...
    (microsoft.public.windows.group_policy)
  • ptwilliams?
    ... Looking at the event viewer, ... I ran netdiag and get this: ... 'opsw2ksvr1.secfedbank.com': Invalid Credentials. ... answers on technet for LDAP errors and event id:1000, ...
    (microsoft.public.win2000.active_directory)
  • Re: Event ID 108
    ... This is a network I inherited and when looking around in AD I noticed that the "Default Domain Policy" has either been deleted or renamed because it no longer exists. ... I have run dcdiag /fix and netdiag /fix on all DCs and netdiag /fix on the test-deploy workstations, but this has not solved the problem. ... We are planning on upgrading the domain to WS2k3 within the next few weeks. ...
    (microsoft.public.windows.server.active_directory)