Re: IPSec Policy

From: Jordan Samulaitis (jordan_at_jvsDELETEnetworks.com)
Date: 03/01/05


Date: Mon, 28 Feb 2005 20:26:23 -0600

Steven,

Thank you for replying; I am not quite sure if you are understanding my
problem, I made an IPSec AD policy on my windows server 2003 box to
require security for anything that is port 80.

I am getting a page cannot be displayed error... or page unavailable.

The Client is Windows XP PRO and the server is 2003 standard.

My problem is I am getting a page cannot be displayed when trying to connect
to
http://192.168.1.110 <-- my local intranet server.

The policy I created was to make sure everything under port 80 is encrypted.

All Web Traffic - Require Security - Authentication - Kerberos - Tunnel
Endpoint NONE - Connection Type: All

And within that in the IP Filter List I have selected and created a new
IPFilter List "All Web Traffic"

Within there I have selected TCP has a protocol type. and under the set the
ip protocol port: I selected the To this port radio and inputed port 80

I dont know what I am doing wrong here...

Hope this clairifys things for you,

Jordan

"Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
news:u8tny7eHFHA.908@TK2MSFTNGP12.phx.gbl...
> The client computer needs a compatible ipsec policy such as the
> client/respond ipsec policy or a custom policy you create. Also you must
> exempt the domain controller from the ipsec policy with a rule that has a
> permit action for traffic to and from the dc by it's static IP address or
> you will have problems as domain controllers do the authentication. You
can
> use netdiag /test:ipsec to see ipsec info on a Windows 2000 computer
> including any policy assigned and for XP Pro/W2003 use the two IP security
> mmc snapins. --- Steve
>
> http://support.microsoft.com/default.aspx?scid=kb;en-us;254949
>
> "Jordan Samulaitis" <jordan@jvsDELETEnetworks.com> wrote in message
> news:%23eeaaxUHFHA.720@TK2MSFTNGP10.phx.gbl...
> > Hello,
> >
> > I created an IPSec policy for port 80 on my server to require security
> > using
> > AH and ESP. When I logon my workstation to the domain it does not
display
> > the page, but I can view the local server webpage from the server. What
> > do
> > I need to do to my workstation?
> >
> > P.S - I did a gpupdate /force before letting the workstation to logon
the
> > network.
> >
> > Thanks in advance,
> >
> > Jord
> >
> >
>
>



Relevant Pages

  • Re: To IPSec Packet Filter OR Not To IPSec Packet Filter - that is the question
    ... an IPSec policy that should be sufficiently restrictive for your purposes. ... Client's Source port is ANY ... then how can I create an IPSec filter that blocks all ...
    (microsoft.public.win2000.security)
  • Re: IPSec Policy Doesnt Really Block
    ... basic filters to allow port 80 and port 25 inbound from Any to My IP, ... >I have created ipsec policies that work. ... The I add mirrored permit rules for the exceptions such ... >> Here is a list of IPSECPOL.exe commands I am using to create the policy. ...
    (microsoft.public.win2000.networking)
  • Re: IPSec Policy Doesnt Really Block
    ... basic filters to allow port 80 and port 25 inbound from Any to My IP, ... >I have created ipsec policies that work. ... The I add mirrored permit rules for the exceptions such ... >> Here is a list of IPSECPOL.exe commands I am using to create the policy. ...
    (microsoft.public.win2000.security)
  • Re: Securing the communication between all workstations in a domain
    ... I am no expert at Ipsec. ... I would try using the server (request ... security) policy in that OU - the secure policy is rather extreme and can ... exempt the domain controllers from ipsec traffic - a request policy may work ...
    (microsoft.public.win2000.security)
  • RE: Access to well-known ports on Win2K
    ... IPSEc does not provide security at the user level; ... policy - works for all users of the machine; and can allow or block access ... many routes for deployment as you mention: Group Policy; Local Security ... > TCP/IP Filtering does not provide port level security at the ...
    (Focus-Microsoft)