Networking Forums

Networking Forums > Computer Networking > Windows Networking > IPSec policie is not working like it should

Reply
Thread Tools Display Modes

IPSec policie is not working like it should

 
 
Arjen
Guest
Posts: n/a

 
      04-07-2004, 12:02 PM
Hello,

I've got a Windows Server 2003 Web-Edition installed on my webserver
which is placed somewhere else. I designed IP Security policies to
this machine which work fine.
- All inbound ports are blocked at first (no mirroring)
- Inbound Port 80, 443 (http/https) enabled (no mirroring)
- Inbound Port 3389, 6699 (Terminal Services and RDC) enabled from a
specific IP adress (no mirroring)

* Inbound means that the source IP is 'Any IP adress' and the
destination IP is 'My IP adress'.

This works fine! But I can't get the following rules to work. They are
a little redundant, but nevertheless they should work I think. My
question is how to get these rules to work correctly.

- All Outbound ports are opened (not mirrored)
- Outbound 25 is opened. (not mirrored) (I know this one is also
implied by the upper one but just to make shure.

The problem is I cant vissit any website or send any mail through port
25 to an outside computer. When i unassign the policie everything
works fine! Please help!!!

Greetings

Arjen
 
Reply With Quote
 
 
 
 
David Beder [MSFT]
Guest
Posts: n/a

 
      04-08-2004, 07:21 AM
I'm not sure how you can force all your traffic to go out a single port.
Almost all of your applications are going to be given dynamic outbound ports
(ie they'll get a different one each time). Do you have some sort of port
translation software? Even if you did get this to happen or instead use the
dynamic outbound port, that will let you push traffic out, but when it
returns, your inbound filters are going to block it.

It sounds like you're looking for a firewall, not data protection.

--
David
Microsoft Windows Networking
This posting is provided "AS IS" with no warranties, and confers no rights.


"Arjen" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed) om...
> Hello,
>
> I've got a Windows Server 2003 Web-Edition installed on my webserver
> which is placed somewhere else. I designed IP Security policies to
> this machine which work fine.
> - All inbound ports are blocked at first (no mirroring)
> - Inbound Port 80, 443 (http/https) enabled (no mirroring)
> - Inbound Port 3389, 6699 (Terminal Services and RDC) enabled from a
> specific IP adress (no mirroring)
>
> * Inbound means that the source IP is 'Any IP adress' and the
> destination IP is 'My IP adress'.
>
> This works fine! But I can't get the following rules to work. They are
> a little redundant, but nevertheless they should work I think. My
> question is how to get these rules to work correctly.
>
> - All Outbound ports are opened (not mirrored)
> - Outbound 25 is opened. (not mirrored) (I know this one is also
> implied by the upper one but just to make shure.
>
> The problem is I cant vissit any website or send any mail through port
> 25 to an outside computer. When i unassign the policie everything
> works fine! Please help!!!
>
> Greetings
>
> Arjen



 
Reply With Quote
 
Arjen Steur
Guest
Posts: n/a

 
      04-14-2004, 07:09 AM
Eventualy I posted my problem a little to complicated; I'll simplifie my
problem a little bit.

I'm running a webserver on which port 80 (http) inbound, and port 25 (smtp)
outbound have to be enabled.
the rest has to be blocked. My question is: Is it possible to achieve this
by using IP Securtity Policies which I prefer because it helps to keep my
server clean. If it isn't possible, which firewall would you suggest?

Greetings,

Arjen
Dijkoraad-Hawar BV

"David Beder [MSFT]" <(E-Mail Removed)> schreef in bericht
news:(E-Mail Removed)...
> I'm not sure how you can force all your traffic to go out a single port.
> Almost all of your applications are going to be given dynamic outbound

ports
> (ie they'll get a different one each time). Do you have some sort of port
> translation software? Even if you did get this to happen or instead use

the
> dynamic outbound port, that will let you push traffic out, but when it
> returns, your inbound filters are going to block it.
>
> It sounds like you're looking for a firewall, not data protection.
>
> --
> David
> Microsoft Windows Networking
> This posting is provided "AS IS" with no warranties, and confers no

rights.
>
>
> "Arjen" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed) om...
> > Hello,
> >
> > I've got a Windows Server 2003 Web-Edition installed on my webserver
> > which is placed somewhere else. I designed IP Security policies to
> > this machine which work fine.
> > - All inbound ports are blocked at first (no mirroring)
> > - Inbound Port 80, 443 (http/https) enabled (no mirroring)
> > - Inbound Port 3389, 6699 (Terminal Services and RDC) enabled from a
> > specific IP adress (no mirroring)
> >
> > * Inbound means that the source IP is 'Any IP adress' and the
> > destination IP is 'My IP adress'.
> >
> > This works fine! But I can't get the following rules to work. They are
> > a little redundant, but nevertheless they should work I think. My
> > question is how to get these rules to work correctly.
> >
> > - All Outbound ports are opened (not mirrored)
> > - Outbound 25 is opened. (not mirrored) (I know this one is also
> > implied by the upper one but just to make shure.
> >
> > The problem is I cant vissit any website or send any mail through port
> > 25 to an outside computer. When i unassign the policie everything
> > works fine! Please help!!!
> >
> > Greetings
> >
> > Arjen

>
>



---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.633 / Virus Database: 405 - Release Date: 18-3-2004


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
New (2008 / Lognhorn) IPSec (Offline request) certificates not working on XP Jarryd Windows Networking 0 01-22-2008 02:15 PM
IPv6 + IPsec + ipsec-tools 0.6.[4567] + scope:link = no SA established phil-news-nospam@ipal.net Linux Networking 0 07-25-2007 09:01 PM
IPSEC policy - replication not working Ketil Windows Networking 0 06-28-2007 11:18 AM
IPSec Blocking is not working Kevin K Windows Networking 1 04-16-2007 02:11 PM
IPSec: net-to-net config not working Jarek Linux Networking 4 08-29-2005 07:33 AM



1 2 3 4 5 6 7 8 9 10 11