Networking Forums

Networking Forums > Computer Networking > Windows Networking > Ipsec and traffic to various ports

Reply
Thread Tools Display Modes

Ipsec and traffic to various ports

 
 
Ekhan
Guest
Posts: n/a

 
      10-28-2006, 06:23 PM
Hi,

I have been asked by a financial institution to implement ipsec on the
network. Unfortunately, I assumed that this would be easy- just turn on the
'Require Secure' policy under 'Domain Security Policy', and use kerberos
authentication- all of the clients are running 2K Pro and XP Pro and should
respond with ipsec...

After turning the policy on, I quickly learned that no one could connect to
webmail. Also, I am guessing that remote users connected through the Cisco
VPN would also have a problem, though we are using radius authentication,
which authenticates them on the domain.

Anyway, is there a way to implement ipsec, so that external users will still
have access to webmail and network resources? I am guessing that I can
filter communication between the front-end Exchange server and the backend,
but I do not know for sure. And I do not know whether vpn users will have
access to anything. Any information about this would be greatly appreciated.

Thanks in advance.


 
Reply With Quote
 
 
 
 
James McIllece [MS]
Guest
Posts: n/a

 
      10-30-2006, 07:01 PM
=?Utf-8?B?RWtoYW4=?= <(E-Mail Removed)> wrote in
news:B10C163C-2154-4F0D-B2BA-(E-Mail Removed):

> Hi,
>
> I have been asked by a financial institution to implement ipsec on the
> network. Unfortunately, I assumed that this would be easy- just turn
> on the 'Require Secure' policy under 'Domain Security Policy', and use
> kerberos authentication- all of the clients are running 2K Pro and XP
> Pro and should respond with ipsec...
>
> After turning the policy on, I quickly learned that no one could
> connect to webmail. Also, I am guessing that remote users connected
> through the Cisco VPN would also have a problem, though we are using
> radius authentication, which authenticates them on the domain.
>
> Anyway, is there a way to implement ipsec, so that external users will
> still have access to webmail and network resources? I am guessing
> that I can filter communication between the front-end Exchange server
> and the backend, but I do not know for sure. And I do not know
> whether vpn users will have access to anything. Any information about
> this would be greatly appreciated.
>
> Thanks in advance.
>
>
>


Yes there is a way to do this -- IPsec allows you to configure IP filters
for specific traffic, which is what you need to do. This is a fairly
complex topic and deployment, and you should implement this in a test lab
first.

You can find answers to all of your questions at the IPsec TechNet site at
http://www.microsoft.com/technet/its...c/default.mspx


--
James McIllece, Microsoft

Please do not send email directly to this alias. This is my online account
name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IPsec tunnel up but no traffic wamsterdam@zesgoes.nl Linux Networking 6 08-14-2008 09:05 AM
IPSec Policy Agent closes SMTP Ports PCGenieLA Windows Networking 0 07-16-2005 02:07 PM
IPSEc Policy Agent closes SMTP ports PCGenieLA Windows Networking 0 07-16-2005 02:05 PM
IPSec Policy Agent closes SMTP ports PCGenieLA Windows Networking 0 07-15-2005 10:59 PM
IPSec filters and ranges of ports Matt Windows Networking 0 09-28-2004 02:32 PM



1 2 3 4 5 6 7 8 9 10 11