Re: Configuring Port range in IPsec

From: David Beder [MSFT] (dbeder_at_online.microsoft.com)
Date: 01/09/05

  • Next message: Herb Martin: "Re: Configuring Port range in IPsec"
    Date: Sun, 9 Jan 2005 01:12:41 -0800
    
    

    It sounds like you want a firewall and not really looking to use IP
    security. IPSec is intended to validate traffic between two trusted peers,
    either for all traffic, or maybe for select traffic used by a client/server
    application. The Windows implementation does not support ranges (yet?) and
    it is near impossible to create/apply a policy with individual filters for
    each port (what did you want for ports 20k-64k?) both tcp and udp.

    -- 
    David
    Microsoft Windows Networking
    This posting is provided "AS IS" with no warranties, and confers no rights.
    "Andras" <Andras@discussions.microsoft.com> wrote in message 
    news:95B7BAC4-C854-47F9-B8C0-399E3D021168@microsoft.com...
    > We would like to add a rule to the IPsec config with the following
    > specification
    > Ports from 10000-20000 are open for all connections from segment 10.4.90.*
    > Ports from 0-10000 are closed for all connections from segment 10.4.90.*
    >
    > I don`t see anything in the configuration possibilities indicating that we
    > can specify a port range and a specify a segment.
    >
    > How can I configure this roule in IPsec or some whereelse on windows 2000
    > advanced server ? 
    

  • Next message: Herb Martin: "Re: Configuring Port range in IPsec"

    Relevant Pages

    • Configuring Port range in IPsec
      ... Ports from 10000-20000 are open for all connections from segment 10.4.90.* ... can specify a port range and a specify a segment. ...
      (microsoft.public.win2000.security)
    • Re: assigning ip addresses on a secure way
      ... > superscope scenario to configure the DHCP to assign 10.3.ip s just to the ... >> allows you to filter mac addresses in a learn mode that can lock ports to ... >> configurations and can allow all computers internet access while not ... >> Within a domain ipsec by default will use kerberos authentication and any ...
      (microsoft.public.security)
    • Re: I am sick of windows firewall
      ... the XP FW if you need to stop outbound packets. ... I have made my adjustments to IPsec to supplement BlackIce ... the Windows networking ports even though BI was stopping ...
      (comp.security.firewalls)
    • Re: Windows 2003 Server RRAS and IPSEC
      ... You can check out the following link for info regarding the ports to be ... parallel firewalls or utilize filters like IPSEC to protect our servers (we ... 443, our campus DNS servers, and campus time servers. ... our campus dialup service then dialed the vpn connection to the new RRAS ...
      (microsoft.public.win2000.ras_routing)
    • Re: Win2K Security & Firewall - long post
      ... for your other ports. ... >>at implementing an IPSec policy on Win2K for extra security. ... >>Today I went a stage further and did a fresh installation of Win2K, ... number of programs that use secondary connections. ...
      (comp.security.firewalls)