Userrights for VPN IPSec connection ?

From: Thomas (spindu@chefmail.de)
Date: 02/19/03


From: "Thomas" <spindu@chefmail.de>
Date: Wed, 19 Feb 2003 08:42:33 -0800


Hello,

I've set up a VPN implementation based on IPSec for remote
clients to connect to company headquarter. The clients OS
is Windows XP Proffesional, they dial in to ISP, get a
dyn. IP address and via script an local IPSec IP Security
Policy will installed. Everything works fine if I logged
in in Windows with Administrator rights. If I log in as a
Main User I can not implement the Security Policy. The
script based on ipseccmd commands gets the error: "Error
converting policy:0x5". If I try to implement the local
policy manual in the MMC, I get the error message "Access
denied".

Do I have to give my clients admin rights to implement an
IP policy or is there a way to handle this with any
configuration of userright / security policies ?

The background is, that I don't want to give "regular"
users adminrights, cause they can install software, change
any configuration, etc ....

Are there any possibilities? Any help would be fine.
Thanks in advance and Bye

Thomas Bogdahn.



Relevant Pages

  • Re: IpSEC in Windows an Unix system
    ... create an ipsec policy for Windows 2000/XP Pro/W2003 domain computers via ... Windows comes with three default configured ipsec policies ... ipsec security associations with Windows 2000 computers and the mmc Ipsec ...
    (microsoft.public.win2000.security)
  • Re: Scripted IPSec policies on Windows XP (without AD/GPOs)
    ... ipsec policy configuration tool that will run on both XP and Win2k3. ... technet piece by Steve Riley provides a more detailed overview of the IPSec ... Scripted IPSec policies on Windows XP ... it seems netsh ipsec commands are only supported ...
    (Focus-Microsoft)
  • RE: Assigning New IPSec Policy to terminal server
    ... the " Create an IPSec filter list to match the Terminal Services ... enable the policy" steps should be completed on Terminal server side. ... Enable the Client policy on the Terminal Services clients" ...
    (microsoft.public.windows.terminal_services)
  • Re: Re: IPSEC in tunnel mode ( possible? )
    ... If I canīt get windows doing it right by itself Iīm already considering ... IPSEC in tunnel mode (possible? ... I, trying to secure a wireless link, want to have my clients using ... To unsubscribe, ...
    (freebsd-isp)
  • Re: Security update pulled back
    ... Recommended Update for Windows XP ... This update to internet Protocol Security Clients IPSec and L2TP/IPSec ... update if they use IPSec and/or L2TP Virtual Private Network ...
    (microsoft.public.security)