Re: Using IPSec; Firewall breaks sysvol replication



Did you check this article?

Active Directory Replication over Firewalls
http://technet.microsoft.com/en-us/library/bb727063.aspx

There you can find a special topic for IPSec: Encapsulating Inside IPSec

Hope it helps

Cheers

--

augusto alvarez | it professional
MCP - MCTS - MCITP DBA
http://blog.augustoalvarez.com.ar/


"brad" <piraparana@xxxxxxxxxxxxxxxx> wrote in message news:F7461A70-0A3B-4AA8-BC8E-9C5D13F13DF6@xxxxxxxxxxxxxxxx
Greetings,

I am using an IPSec policy to enforce the use of IPSec for all network
traffic between domain controllers. The appropriate security associations are
showing up in the IPSec monitor and each domain controller can ping the other
one. Active directory synchs OK. I can add or delete or disable an account on
one DC and the changes show up right away on the others.

However, I am having trouble with Sysvol replication. Sysvol will not
replicate as long as the firewall is enabled on the DC with the PDC role. I
have the following rule in the Windows Firewall to enable IPSec traffic to
pass (using "define ports" setting in GPO):

50:ip protocol:*:enabled:IPSec ESP
51:ip protocol:*:enabled:IPSec AH

We have two root DCs and three child domain DCs. Sysvol works fine on the
child domain. Since it was not working on the root domain, I configured a
static port for FRS, as per KB319553 and enabled that port on all DCs. That
did not solve the problem. Actually, that step should not have been necessary
anyway since all traffic is between DCs is already encapsulated with IPSec.

Summary: 5 domain controllers, all using IPSec, all firewalls configured
identically, yet one server's firewall, when enabled, breaks replication of
sysvol for root domain. Sysvol replication works OK for child domain but not
for root domain.

It would seem that the problem lies with the firewall configuration on the
DC with the PDC role. However, if the firewall was misconfigured, it seems
that no traffic at all could pass between the two root DCs, since all traffic
must use IPSec.


QUestions:
(1) Am I using the syntax correct for the Windows firewall rule to allow
IPSec traffic to pass?
(2) If not, how is it that IPSec is working on all 5 DCs?
(3) On Windows 2003 Server SP2 ; does IPSec traffic bypass the firewall by
default? I do not have the "Windows Firewall:Allow authenticated IPSec
bypass" policy configured.
(4) Would the above-mentioned policy setting be the best way to get around
this problem? If so, I need some help with the SDDL string. My DCs are in an
OU but not in a group. Must I create a group for them in order to be able to
have an SID for the SDDL?


Thanks for any help you can give.
--
bb

.



Relevant Pages

  • Re: sysvol replication breaks when IPSec running between DCs & firewal
    ... Also have a look here about UDP port 500: ... open the firewall for ports required by IPSec, ... We have two root DCs and three child domain DCs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: International AD
    ... 1- You should know that somehow all DCs must replicate with each other ... You can Stop replication by unpluging ... lingering objects when you plug those DCs again to the network. ... IPSec should be invisible for the clients, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Win2K Security & Firewall - long post
    ... IPSec, and more so some reasons why it might be a bad idea for MS to ... realize that tailoring an IPSec policy for a specific home user, ... disabled their personal firewall. ... Won't work if the malware uses a "legitimate" means of disabling ...
    (comp.security.firewalls)
  • Re: Isolate systems
    ... some sort of port/protocol/Ip/mac"filtering" via switches, ipsec filtering, ... firewall yourself from outside the network, even if you use a self scan site ... If legitimate users are trying to attack your computers you may have to see ...
    (microsoft.public.win2000.security)
  • Re: sysvol replication breaks when IPSec running between DCs & fir
    ... IPSec" as per as per Steve Riley ... I do not know how to write a firewall rule to ensure that IP ... Riley says you can "Encapsulate domain controller traffic inside ... the IPsec exists underneath the Windows Firewall ...
    (microsoft.public.windows.server.active_directory)

Loading