Re: IPSec



Wow. Whoever is telling you this must be on some really good drugs! Non-domain computers cannot do any kind of Kerberos communications at all.

--
Steve Riley
steve.riley@xxxxxxxxxxxxx
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


"John" <John@xxxxxxx> wrote in message news:OXuv6ol9HHA.4584@xxxxxxxxxxxxxxxxxxxxxxx
That's what I thought
I've been told that creating a IPSec policy and configuring that IPSec policy in some servers in domain using only AH (Authentication Header) using Kerberos authentication would work for comunication witrh XP machines not members of the domain.
Does this sounds correct for you?
Thanks for your time.



"Brian Komar" <brian.komar@xxxxxxxxxxxxxxxxx> wrote in message news:e3YqWZa9HHA.2752@xxxxxxxxxxxxxxxxxxxxxxx
Not going to work. Computers in a workgroup do not do Kerberos
Your only two choices are shared secret or certificates
Why are certificates not an option?
Brian

"John" <John@xxxxxxx> wrote in message news:uRj9nzY9HHA.1188@xxxxxxxxxxxxxxxxxxxxxxx
Hi everyone,

Is it possible to make a computer in a workgroup to "talk" with a server/computer that belongs to a domain using IPSec.

I'm not talking a bout VPN, both machines are in the same physical network and authentication using certificates isn't a option, so all I can use is Kerberos.




.



Relevant Pages

  • Re: IPSec
    ... than try to do stupid configurations. ... Non-domain computers cannot do any kind of Kerberos communications at all. ... policy in some servers in domain using only AH (Authentication Header) ... Your only two choices are shared secret or certificates ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... until a user logon event. ... the Netdiag utility will show the Kerberos error in this scenario ... On these machines I ... me a plausible starting point to solve my Kerberos authentication problem. ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... I just wanted to let you know there is a known bug in netdiag that reports ... >> mean that kerberos authentication is not being used. ... Three machines are workstations and three are ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... I installed the Resource Kit. ... > mean that kerberos authentication is not being used. ... Three machines are workstations and three are ...
    (microsoft.public.windows.server.security)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... Kerberos result when I hardwired a laptop to a switch port. ... to authenticate with K on reboot AND authentication appears to take place ... > denied access until you can authenticate to a domain controller as a user. ... > You should have logging of account logon events enabled in Domain Controller ...
    (microsoft.public.windows.server.security)