Verify IPSec policies are running on XP and 2003



Looking to figure out how to verify if the IPSec policies from the
domain are in place (and running) on an XP Pro box (sp2).

IP Sec policy "Request Security" was created and linked as follows:

Domain (Primary.XYZ.INT) : Request Security
-- Server1

OU (Test_Policies) : Request Security
-- Test (Test user)

I set the Domain policy with the No Override switch and stuck it at
the top of the GPO links. I left the OU link with the defaults (it's
in as a secondary for this test).

RSOP on the XP box under the admin account doesn't display IPSec
settings in either the Computer config or User config containers.
Running it for the Test user also shows no IP settings. Running RSOP
on the Server using the Admin account shows no settings either.

Properties on the Computer Config show the Request Security GPO at the
top of the list and being applied. No other polices (including local)
have had any IP security parameters defined (the one or two I toyed
with are pretty much blank). ACL's on the policies appear correct.
Local security settings on the XP box indicate no policies are
assigned at the local level either.


So, is there a manual way I can verify the IPSec connection? I had
attempted a simple ping to the server to see if security negotiation
would be displayed, but no dice. Reply's came back instantly.
Thinking maybe using the event viewer on the XP box, but not sure how
to configure it for this test.

TIA.

Paul

.



Relevant Pages

  • RE: Using IPSEC to block IP
    ... Using IPSEC to block IP ... > anything with either IIS or WebBoard. ... I use the IPSec settings to assign complete packet filter settings to a hurd ... You DO need an Active Direcotry in place, otherwise centralized policies ...
    (Focus-Microsoft)
  • Re: Question about Windows 2000 and IE?
    ... IE's settings are all normal, no policies that I know of. ... but after searching help I found something ... called IPSec. ...
    (microsoft.public.win2000.security)
  • IPSEC between Member Server and Domain Controller - How?
    ... I have a Windows 2000 Member Server and a Domain Controller. ... When I open the firewall communication between the DC ... and the Member Server is fine with IPSEC flowing freely (monitored using ... using the "Request Security" model as opposed to the "Require Security". ...
    (microsoft.public.win2000.security)

Quantcast