KB article 324261 shows how to secure SNMP traffic with an IPSec policy. This
is my first IPSec policy on Win2K3, so I may have something wrong, but there
seems to be a big piece missing. I run Dell Openmanage ITA on my Win2K3 box.
When it queries managed systems via SNMP, the queries are sent from a random
high port to port 161 (UDP). The response, is from port 161 (UDP) to the
random high port.
The directions in the article only cover traffic that comes from AND goes to
port 161, which is basically never. So the filter never matches, the policy
never applied. In my testing and monitoring with Ethereal, this is the case.
Should there not be 8 rules in the filter altogether (ie TCP, 161 to any AND
TCP, any to 161)?
|