Re: Configuring Port range in IPsec

From: Herb Martin (news_at_LearnQuick.com)
Date: 01/09/05


Date: Sun, 9 Jan 2005 05:18:18 -0600


"Steve Riley [MSFT]" <steriley@microsoft.com> wrote in message
news:41300632408220999452032@news.microsoft.com...
> Remember that IPsec is really about creating authenticated and
(optionally)
> encrypted security associations between a pair of computers. Given that
primary
> design goal, it appears that port ranges aren't something that's required.

I disagree -- that may have been the original intention,
but it allows for three actions: Pass, Block, or negotiate
actual IPSec services.

The BLOCK and PASS are not only useful without
the IPSec they are better than any other built-in (and
ubiquitous) Windows blocking mechanism.

> I'm guessing that you'd like port ranges for simple block/allow rules --

For me you are largely correct.

> using the IPsec engine as a packet filter. Is that right? Or do you have
> a need for security associations with port ranges?

Someone might -- IPSec is vastly underutilized
by the majority of admistrators.



Relevant Pages

  • Re: Configuring Port range in IPsec
    ... Remember that IPsec is really about creating authenticated and ... encrypted security associations between a pair of computers. ... it appears that port ranges aren't something that's required. ... using the IPsec engine as a packet filter. ...
    (microsoft.public.win2000.security)
  • Re: Configuring Port range in IPsec
    ... prefer that people use real host firewalls for block/allow; ... People have been requesting port ranges in the IPsec engine for a while, ... >> encrypted security associations between a pair of computers. ...
    (microsoft.public.win2000.security)
  • Re: IPSec bandwidth usage
    ... of client computers to see if security associations are occuring and if ... add rules to your ipsec policies to exempt dns udp for better ... > increase in bandwidth usage since IPSec was supposedly working, ...
    (microsoft.public.win2000.security)
  • Re: IPSEC with pre-shared key VPN setup
    ... Try using ipsecmon to view if the Security Associations are being created or not. ... Network access over an ipsec tunnel can be slow and netbios name resolution probably ... > then I can ping addresses in the remote network. ...
    (microsoft.public.win2000.networking)
  • Re: Isolate systems
    ... If you have access to the firewall, you might be able to configure what IP ... filtering policy on your computers which is a policy that uses rules with ... Ipsec policies are best when trying to configure for a subnet ... network layout you may be able to implement ...
    (microsoft.public.win2000.security)