Initial IPSEC policy

From: Harald Haitsma (haraldhaitsma_at_hotmail.com)
Date: 01/27/04


Date: Tue, 27 Jan 2004 20:44:28 +0100

I Have a Win2003 Domain with only WinXP clients.

On a Win2000 Server i read following:
Using IP Security (IPSec) to protect traffic from a non-domain member to the
domain controller is currently not supported in Windows 2000 because it is
not possible for non-domain computers to get the initial IPSec policy from
the domain controller once a domain controller (DC) requires IPSec to
communicate, and because non-domain member computers cannot use Kerberos as
the IPSec/IKE authentication method to authenticate IKE with their domain
controller and with trusted domain controllers on the domain in all cases.

Is this changed within XP and 2003?

Thxs



Relevant Pages

  • Re: Initial IPSEC policy
    ... kerberos authenticated IPSec communication across the board. ... > Using IP Security to protect traffic from a non-domain member to ... > domain controller is currently not supported in Windows 2000 because it is ... > the IPSec/IKE authentication method to authenticate IKE with their domain ...
    (microsoft.public.windows.server.security)
  • Re: IPSec / domain isolation: confusing MS documents
    ... private notebook can not attach to ressources on the server with his user ... simply not possible using ipsec and that is their choice. ... The user right for access this computer from the network will not work ... account, disabling unneeded services on the domain controller, and using ...
    (microsoft.public.windows.server.security)
  • Re: Mapping drives and Encryption
    ... ipsec newsgroup involving those on the ipsec team at MS being asked if this ... Ipsec is supported for domain controller to ... authentication traffic will be blocked and IPSec ... > getting the certificate server setup right. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: prevent access to shared folder when not on a domain computer
    ... As Roger mentioned ipsec is the technology to accomplish what you want to do ... the file share to a non domain controller was a good suggestion. ... a copy for your records that prohibits unauthorized computers on the ... > able to use ipsec on my server. ...
    (microsoft.public.windows.server.security)
  • Re: IPSEC between Member Server and Domain Controller - How?
    ... I am specifically trying to get Domain Member Domain Controller traffic ... to go via IPSEC when the IPSEC policy is applied using a GPO. ... > You can use the firewall log as a diagnostic tool: ...
    (microsoft.public.win2000.security)