IPSEC Help

From: BobS (bobs_at_qqq.com)
Date: 10/22/03

  • Next message: Vicky Sam: "Can i use .net framework for security"
    Date: Tue, 21 Oct 2003 18:13:45 -0400
    
    

    I have a 2003 AD. All of my servers, and workstation are WIN2003 servers,
    and WIN XP Pro workstations. I'm tryning to get IPSEC to work without
    success. I stood up a test WIN2003 server. I created a Test OU. I created a
    test IPSEC policy, and applied it this test OU. The only setting in the
    policy is IPSEC assign Server (request security) policy. After I apply this
    policy to this OU I waite five minutes, and reboot the server. The server
    comes back up, It says it's appling the computer settings. It appears to get
    the IPSEC policy, and then stops communicating with the doamin controller. I
    then get Netlogon errors, usernv errors, w32 errors. I then go to a
    workstation and ping the workstation, and it responds so I know ICMP is
    working, and not encrypted. I then try to map a drive, or hit share on the
    server and I get an error "Event ID: 547" IKE Main mode negotiation failed.
    This the canned IPSEC policy I'm dealing with here. The negotiating method
    on the policy is kerboros, and the AD uses Kerboros. Also all computers have
    machine certificates issued to them via autoenrollment. Anyone have any
    ideas.

    bobs@itproscorp.com


  • Next message: Vicky Sam: "Can i use .net framework for security"

    Relevant Pages

    • Re: Securing the communication between all workstations in a domain
      ... I am no expert at Ipsec. ... I would try using the server (request ... security) policy in that OU - the secure policy is rather extreme and can ... exempt the domain controllers from ipsec traffic - a request policy may work ...
      (microsoft.public.win2000.security)
    • Re: Local Security Policy Locked (or something?)
      ... at one time I may have been booting the server ending up ... for the local workstation. ... Failed to open IPsec policy storage Access is ... or not a given security setting is defined in group policy. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Require connecting systems to be a Domain Computers
      ... something in which I include the group Domain Computers. ... >kerberos computer authentication for the ipsec SA then the computer must be ... In such case the server must not be a domain controller, ... >ipsec require policy will need to exempt all domain controllers with a rule ...
      (microsoft.public.security)
    • Server-based group policy without active directory?
      ... policy forum I saw... ... enable roaming user profiles for our office where anyone can sit down ... The policy information itself should be stored on our server (win ... workstation to look to the provided path for user settings. ...
      (microsoft.public.win2000.group_policy)
    • Re: lan ipsec ws2003 / xp pro deplyoyment
      ... Remote Access on the server and configure it and then configure your XP computer to ... preshared key for machine authentication. ... If you use ipsec pre shared key [policy/all ... You could go to Local Security Policy of each ...
      (microsoft.public.windowsxp.security_admin)