Re: Configuring Port range in IPsec

From: Herb Martin (news_at_LearnQuick.com)
Date: 01/08/05


Date: Sat, 8 Jan 2005 03:29:46 -0600


"Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
news:uCITVjO9EHA.3416@TK2MSFTNGP09.phx.gbl...
> You can not configure a port range in a single filter entry for an ipsec
> policy. You can either use an IP address or subnet when creating a filter
> entry for an ipsec rule. --- Steve
>

It's one of the serious weaknesses of the IPSec
filter rules.

I wrote a "generator" in Perl which builds the
IPSec rules from a table (sort of) because at
least one of my machines runs close to a 1000
rules/filter sets.

Even this is not a full solution because at a 1000
rules it can significantly impact the machines
performance for up to an hour when the rules are
re-applied.

Better would be for the filters to accept such
information and handle it efficiently.

-- 
Herb Martin


Relevant Pages

  • Re: [Win2k] Stopping sw from phoning home
    ... You can use an ipsec filttering policy that contains a rule that has a ... filter list with those IP addresses and a block filter action. ... below may also be of help in that it shows the basics of an ipsec filtering ... or a tool such as port reporter as shown in the link below. ...
    (microsoft.public.win2000.security)
  • Re: To IPSec Packet Filter OR Not To IPSec Packet Filter - that is the question
    ... an IPSec policy that should be sufficiently restrictive for your purposes. ... Client's Source port is ANY ... then how can I create an IPSec filter that blocks all ...
    (microsoft.public.win2000.security)
  • Re: p Security GPO Setup
    ... Workstations to Their Own OU with Client Respond. ... > Your require/request ipsec policy would need to exempt domain controllers by ... > their static IP address which would include then within a permit filter ...
    (microsoft.public.windows.server.security)
  • Re: IP SEC filtering issue
    ... different machines. ... the IPSEC processing gets done it the kernel, ... > filter out the syn packet and using divert sockets (we have a lot ... > If any of you know of a way to get ipsec to filter on syn packets ...
    (FreeBSD-Security)
  • Re: Problem with IPSEC
    ... It is not unusual not to be able to access a website by entering the IP ... troubleshooting ipsec rules. ... protocol:TCP, and filter action permit. ... I have tried other web sites too and couldn't connect with the IPSEC ...
    (microsoft.public.windows.server.security)