Networking Forums

Networking Forums > Computer Networking > Windows Networking > IPSec policy on servers connected to 2 networks

Reply
Thread Tools Display Modes

IPSec policy on servers connected to 2 networks

 
 
Stuart
Guest
Posts: n/a

 
      11-18-2007, 05:08 PM
Hi. I am currently investigating how to setup an IPSec policy on a small
network (single domain) of ~20 windows 2003 and 2000 servers and ~10 windows
xp and 2000 workstations. Of the 20 servers 5 of them are directly
connected to other networks via a second nic, the IP address ranges of these
second network connections also vary.

If possible can anyone advise how I can deploy a policy to enable IPSec on
the internal domain traffic while still allowing these 5 servers to continue
communicating to their second network in the clear ? I'm comfortable with
setting up IPSec, it's how to handle the two network issue I'm stuck on.

Thanks,
Stuart.

 
Reply With Quote
 
 
 
 
Steve Riley [MSFT]
Guest
Posts: n/a

 
      11-20-2007, 03:20 AM
Except for when you indicate the interface type (all, LAN, or remote), the
IPsec engine doesn't care about interfaces -- it concerns itself only with
IP addresses and any rules that match those addresses.

What kind of policies do you want on the internal domain?


--
Steve Riley
(E-Mail Removed)
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


"Stuart" <newsgroups> wrote in message
news:(E-Mail Removed)...
> Hi. I am currently investigating how to setup an IPSec policy on a small
> network (single domain) of ~20 windows 2003 and 2000 servers and ~10
> windows xp and 2000 workstations. Of the 20 servers 5 of them are
> directly connected to other networks via a second nic, the IP address
> ranges of these second network connections also vary.
>
> If possible can anyone advise how I can deploy a policy to enable IPSec on
> the internal domain traffic while still allowing these 5 servers to
> continue communicating to their second network in the clear ? I'm
> comfortable with setting up IPSec, it's how to handle the two network
> issue I'm stuck on.
>
> Thanks,
> Stuart.


 
Reply With Quote
 
Roger Abell [MVP]
Guest
Posts: n/a

 
      11-20-2007, 02:59 PM
Instead of defining your rules as to/from My Address define
them using to/from IP of concern for the traffic type.

"Stuart" <newsgroups> wrote in message
news:(E-Mail Removed)...
> Hi. I am currently investigating how to setup an IPSec policy on a small
> network (single domain) of ~20 windows 2003 and 2000 servers and ~10
> windows xp and 2000 workstations. Of the 20 servers 5 of them are
> directly connected to other networks via a second nic, the IP address
> ranges of these second network connections also vary.
>
> If possible can anyone advise how I can deploy a policy to enable IPSec on
> the internal domain traffic while still allowing these 5 servers to
> continue communicating to their second network in the clear ? I'm
> comfortable with setting up IPSec, it's how to handle the two network
> issue I'm stuck on.
>
> Thanks,
> Stuart.



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need help with ipsec policy Jim H Windows Networking 1 09-05-2008 02:49 PM
IPSEC policy - replication not working Ketil Windows Networking 0 06-28-2007 11:18 AM
IPSec Policy Agent closes SMTP Ports PCGenieLA Windows Networking 0 07-16-2005 02:07 PM
IPSEc Policy Agent closes SMTP ports PCGenieLA Windows Networking 0 07-16-2005 02:05 PM
IPSec Policy Agent closes SMTP ports PCGenieLA Windows Networking 0 07-15-2005 10:59 PM



1 2 3 4 5 6 7 8 9 10 11