Re: IPSec on webserver



Hi,

As long as server is not part of domain it won't be able to use Kerberos as
authentication and it will either use certificates or pre-shared secret
depending on your configuration. Kerberos only works in domain.

What is your goal with these filters? Just filtering traffic or also
encrypting it between server and your network?

--
Mike
Microsoft MVP - Windows Security

<rolf@xxxxxxxxxxxx> wrote in message
news:1160034545.449588.317000@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi all,

Im using IPsec to help lock down a webserver. I have a simple block
rule for all UDP and TCP traffic then various rules to allow sql server
trafic from 'allowed' IPs, terminal services and https, http traffic
plus ftp. Most of the ruleset I originally copied from here;

http://homepages.wmich.edu/~mchugha/w2kfirewall.htm

The webserver is not part of any domain and is hosted remotely.

At the local office the intranet runs behind a public IP. That IP is
given access through the IPsec policy. It does work but periodically
the connection takes 5-10 seconds to authenticate. Without the IPsec
policy enabled it is instantaneous.

The local intranet is on a domain with AD and DHCP etc. DNS resolving
is done via the router, no netbios is used.

Is there something I should do at the intranet end to 'help' this speed
issue...?

Any help greatly appreciated as Im having no luck.

PS Ive also tried reducing the number of rules (there were only 6 or so
anyways), everything is set to authenticate using kerbos.



.



Relevant Pages

  • Re: NTLM authentication
    ... I can't use kerberos because I am on a Winnt system based on NTML not ... this is a local intranet and you are only running SQL on a server which is not a Domain member and you want to authenticate windows accounts using NTLM? ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Fetch username
    ... you want to authenticate, require the user to authenticate to the ... workstations to login to the Intranet and view the Intranet web pages. ... Windows Intranet server (with Windows Integrated authentication turned ...
    (comp.lang.php)
  • Re: Kerberos Auth using O2k3 and E2k3 in a cluster
    ... >authenticate to our LCS and our DC using kerberos; it's just the Exchange ... They may ask the Exchange server for a GC name, ...
    (microsoft.public.exchange.admin)
  • Re: Kerberos Auth using O2k3 and E2k3 in a cluster
    ... >authenticate to our LCS and our DC using kerberos; it's just the Exchange ... They may ask the Exchange server for a GC name, ...
    (microsoft.public.outlook)
  • Re: Kerberos Auth using O2k3 and E2k3 in a cluster
    ... >authenticate to our LCS and our DC using kerberos; it's just the Exchange ... They may ask the Exchange server for a GC name, ...
    (microsoft.public.exchange.clients)