Networking Forums

Networking Forums > Computer Networking > Windows Networking > IPSec transport mode with Kerberos authentication

Reply
Thread Tools Display Modes

IPSec transport mode with Kerberos authentication

 
 
RJ
Guest
Posts: n/a

 
      07-23-2004, 04:53 AM
I have a 2003 DC and a 2003 member server separated by a
firewall that is not doing NAT. I have created an IPSec
transport policy on both servers using source ANY and
destination ANY and mirrored packets is checked and
Kerberos authentication.

I am able to create the tunnel from the DC to the member
server and create an IPSec connection. All traffic flows
fine and I am able to access everything I need to from
both servers.

When I try to create the tunnel from the the member
server to the DC, it states in the Security Log that "no
authority could be contacted for authentication".

If I change the authentication to pre-shared keys I can
create the tunnel in both directions. I have IPSec and
ISAKMP open in both directions as well as trying DNS and
Kerberos, both TCP and UDP in both directions.

When I analyze the traffic, I see the member server
queries the DNS server during boot for an LDAP server,
and the DC never responds. I believe this is the issue
because the member server does not know what server to
query for Kerberos authentication.

Any input will be greatly appreciated.

Thanks,
RJ
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ipsec tunnel mode vs ip in ip with ipsec transport Reji Linux Networking 1 09-20-2011 04:29 PM
IPSec Policy Main Mode and Quick Mode aconti Windows Networking 0 02-25-2009 11:42 PM
IPsec in Transport mode: Linux corrupts TCP traffic?! Mouse Linux Networking 0 08-12-2005 12:35 PM
IPSec in transport mode with non-Windows OS Scott Lowe Windows Networking 0 09-13-2004 05:01 PM
IPSec transport mode or IPSec tunnel mode? Spin Windows Networking 1 07-01-2004 06:32 AM



1 2 3 4 5 6 7 8 9 10 11