Re: Initial IPSEC policy

From: Chris (chris_at_dev.nul)
Date: 01/28/04

  • Next message: RG: "Failure Audit"
    Date: Tue, 27 Jan 2004 16:28:51 -0800
    
    

    No this is still the same in XP and 2003. You are referring to
    http://support.microsoft.com/default.aspx?kbid=254949

    Non-domain members could never join the domain if your DC's required
    kerberos authenticated IPSec communication across the board.

    Chris Weber

    "Harald Haitsma" <haraldhaitsma@hotmail.com> wrote in message
    news:eDS$53Q5DHA.2540@TK2MSFTNGP11.phx.gbl...
    > I Have a Win2003 Domain with only WinXP clients.
    >
    > On a Win2000 Server i read following:
    > Using IP Security (IPSec) to protect traffic from a non-domain member to
    the
    > domain controller is currently not supported in Windows 2000 because it is
    > not possible for non-domain computers to get the initial IPSec policy from
    > the domain controller once a domain controller (DC) requires IPSec to
    > communicate, and because non-domain member computers cannot use Kerberos
    as
    > the IPSec/IKE authentication method to authenticate IKE with their domain
    > controller and with trusted domain controllers on the domain in all cases.
    >
    > Is this changed within XP and 2003?
    >
    > Thxs
    >
    >
    >


  • Next message: RG: "Failure Audit"

    Relevant Pages

    • Re: Mapping drives and Encryption
      ... ipsec newsgroup involving those on the ipsec team at MS being asked if this ... Ipsec is supported for domain controller to ... authentication traffic will be blocked and IPSec ... > getting the certificate server setup right. ...
      (microsoft.public.windowsxp.security_admin)
    • Initial IPSEC policy
      ... Using IP Security (IPSec) to protect traffic from a non-domain member to the ... domain controller is currently not supported in Windows 2000 because it is ... the IPSec/IKE authentication method to authenticate IKE with their domain ...
      (microsoft.public.windows.server.security)
    • Re: IPSEC on Windows 2000 - Help
      ... shouldn't they still be able to communicate? ... It's exempted once the involved computers have negotiated an SA and IPsec is ... > member to the domain controller is currently not supported ... domain authentication to take place to allow communication, ...
      (microsoft.public.win2000.security)
    • Re: IPSEC on Windows 2000 - Help
      ... If Kerberos is one of the "default exemptions" for IPSec ... member to the domain controller is currently not supported ... >initial authentication to the domain never takes place ...
      (microsoft.public.win2000.security)
    • Re: LOB app notebook using Network resources
      ... Why don't you want to join it to the domain as authentication will become ... You can use it as a non-domain member but those authentication ... resources on a member server running 2K3. ... off the notebook to a folder on the 2K3 server. ...
      (microsoft.public.windows.server.sbs)