IPSec / domain isolation: confusing MS documents



We are reserching possibilities to secure Windows 2003 Server SP1 and
Windows XP systems at a customer location with IPSec. All the domain
controllers also host other services like file and printing ressources. Have
read several papers, and whats confusing me is that according to Microsoft,
domain controllers can't be protected at all.



For example, in the Microsoft document "Interoperability Considerations for
IPsec Server and Domain Isolation", downloadable at
http://www.microsoft.com/downloads/details.aspx?FamilyId=10359569-EF11-499A-9E1F-85DA3FCA608C&displaylang=en
is the following text:



"Domain controllers: An IPsec connection between a domain controller and a
domain member is currently not supported, in part because a client must
connect to a domain controller to get a Kerberos ticket and cannot use IPsec
until after it has authenticated. (Although it is possible to use IPsec
between a domain controller and a domain member when certificate
authentication is used, doing so is also not currently supported.)"



Is this statement still correct?

Can someone explain me why it is not possible to secure for example all SMB
traffic with IPSec between domain controllers and client systems?



Thank you all in advance for any help!

Franz


.



Relevant Pages

  • Re: Mapping drives and Encryption
    ... I ran into problems when I first started testing ipsec. ... The reason is that the domain controllers are also the KDC and the computer ... made authentication impossible. ... So then I tried using a request ipsec policy ...
    (microsoft.public.windowsxp.security_admin)
  • Re: authentication problem
    ... double or triple duty most traffic [authentication and AD replication] is ... laptops and I bring up ipsec as a possible solution with the caveat on ... domain controllers because many admins right away want to enable the require ... policy at the domain level which can bring their network to it's knees. ...
    (microsoft.public.win2000.security)
  • RE: authentication problem
    ... IPSec is based on the authentication of computers on a network; ... The Active Directory security domain provides this authentication using the ... are used for communication with domain controllers. ... Directory¨Cbased IPSec policy settings are typically applied to domain ...
    (microsoft.public.win2000.security)
  • Re: Securing the communication between all workstations in a domain
    ... I am no expert at Ipsec. ... I would try using the server (request ... security) policy in that OU - the secure policy is rather extreme and can ... exempt the domain controllers from ipsec traffic - a request policy may work ...
    (microsoft.public.win2000.security)
  • Re: Mapping drives and Encryption
    ... >I ran into problems when I first started testing ipsec. ... >The reason is that the domain controllers are also the KDC and the computer ... >made authentication impossible. ... >policy for the domain controller and it still would not work. ...
    (microsoft.public.windowsxp.security_admin)