Is total domain Isolation possible?



Hello

I am trying to enhance the security on our network by implementing an
"Domain Isolation" solution by using IPsec and group policies.

The enviroment looks like this:
- Small network, only one site.
- Active Directory, 1 domain
- 15 x Windows Server 2003 SP2
- 300 x Windows XP SP2
- 3rd party network attached devices like HP JetDirect

We simply want to isolate the domain totally, as in, all clients and
servers ONLY communicates with IPsec traffic. By doing this, we should
be able to avoid the threat of malicious software introduced by 3rd
party notebooks or unmanaged computers beeing plugged into our
network.

Artickel Q254949 says: "Currently, we do not support the use of IPSec
to encrypt network traffic from a domain client or member server to a
domain controller when you apply the IPSec policies by using Group
Policy or when you use the Kerberos version 5 protocol authentication
method"

I guess that means I will have to use "Request IPsec" instead of
"Require IPsec" on my Domain Controllers, and that means I cant call
it isolated anymore in my opinion.

Is it possible to run a totally isolated domain with 2003/xp or is
this one of those things I will have to wait for Vista/Longhorn to do?

.



Relevant Pages

  • Re: Green Admin - Brute Force Attack - Pls Help
    ... Ipsec configuration is very similar [if ... specifics on how to use ipsec "filtering" policy to protect computers. ... is managing a network - particularly one in a hostile environment. ...
    (microsoft.public.security)
  • Re: Malicious Software Removal Tool Errors Reported
    ... chkdsk while the errors are occuring resolves the problem. ... don't know if the IPsec service is running or not. ... IPSec Services: IPSec Services failed to get the complete list of network ...
    (microsoft.public.windowsxp.general)
  • Re: Hey, folks...I do post. How about a net sec technique revisit?
    ... do it in an IP network. ... I never built such a driver, ... I don't believe IPsec gives this kind of behavior. ... (BTW when we used link passwords in the GE DECnet, they seemed to work fine regardless whether the connection was DDCMP or ethernet.) ...
    (comp.os.vms)
  • Re: IPSec / domain isolation: confusing MS documents
    ... workstation, he is able to attach to server ressources again, but for our ... The user right for access this computer from the network ... will not work for computer accounts unless ipsec is being used. ... securing a domain controller. ...
    (microsoft.public.windows.server.security)
  • Re: asp.net
    ... Snap-in selection in the drop menu, ... pop-up messages from network sense telling you that the ... >>One normally sees the IPsec message that you mention ... >>when one network capable interface has not finished its ...
    (microsoft.public.windowsxp.security_admin)