Re: IPSec to encrypt SMB traffic?

From: Steve Clark [MSFT] (bogus_at_microsoft.com)
Date: 01/17/05


Date: Mon, 17 Jan 2005 11:53:22 -0800

Do you require encryption of this traffic, or just authentication?

You can use IPsec transport mode to secure communications such that any
machine that can not AuthN with IKE will be unable to communicate. This
means that a user will never get prompted for credentials since IKE fails.

"Research Services" <key@lamar.n0-sp@m.colostate.edu.NO> wrote in message
news:uWsyCHp%23EHA.3236@TK2MSFTNGP15.phx.gbl...
>
> Are there any MS KB articles or whitepapers that detail how to use IPSec
> to encrypt SMB traffic?
>
> We are in an Active Directory Forest, and would like to use Group Policy
> to configure IPSec to encrypt SMB traffic between all of our Windows XP
> clients and our Windows 2003 File Servers (using Kerberos). Is it
> possible to set this up so _only_ TCP 445 on _particular_ servers will
> always be encrypted when communicating with our XP clients?
> We are not currently using IPSec and would like to enable encryption for
> ONLY the case mentioned above if possible.
>
> Thanks for any information.
>
>



Relevant Pages

  • RE: Secure / Encrypt Terminal Services
    ... Terminal Services does have decent encryption, ... IPSec is a great solution. ... As for the encryption, I do feel somewhat safe using the built-in ... I would certainly consider additional security. ...
    (Focus-Microsoft)
  • Re: "Linux Shminux - IPsec is Snake Oil!" VMS Mgmnt
    ... In addition to the Apple, IBM, SUN, Microsoft, and HP-UX support for IPsec I ... This was a public company which needed to meet Sarbanes-Oxley regulations and auditing, most of which covered security. ... I couldn't say whether IPSEC or some other form of encryption was really needed or not but I'm reasonably certain that none of my jobs since being discharged from the Army in 1969 used any form of encryption for internal network traffic. ...
    (comp.os.vms)
  • Re: IPSec to encrypt SMB traffic?
    ... Do you require encryption of this traffic, ... You can use IPsec transport mode to secure communications such that any ... means that a user will never get prompted for credentials since IKE fails. ... > Are there any MS KB articles or whitepapers that detail how to use IPSec ...
    (microsoft.public.windows.server.security)
  • Re: IPSec to encrypt SMB traffic?
    ... Can Etercap sniffer/interceptor defeat IPSec? ... > particular Windows 2003 file server. ... Removed all entries under Key Exchange Security Method except ... > Encryption and Integrity Security Method. ...
    (microsoft.public.windows.server.security)
  • Re: IPSec to encrypt SMB traffic?
    ... Can Etercap sniffer/interceptor defeat IPSec? ... > particular Windows 2003 file server. ... Removed all entries under Key Exchange Security Method except ... > Encryption and Integrity Security Method. ...
    (microsoft.public.windowsxp.security_admin)

Loading