IPSEC


i have a customer wants enable encrypted communicatons around 20 servers , 1000 desktops.  subset of around 8000 workstations , 200 servers.  in single ou specific operations.  healthcare requirments need encrypt lan traffic.   thinking using kerberos ipesec policy using "secure server" way initiate encrypting said servers , still able communicate servers not participating in policy. 

 

the question have can create policy ou? reading state enable in default domain policy. cant other reasons.  want servers/clients in ou.

 

i figure kerberos easier implement , dont require internal pki or have deal ssl.

is there anyting might on looking or need condsider? 

i believe can accomplished single gpo linked @ ou correct?

its mix of xp/2003/windows 7/2008.  know need use 3des.


thanks, grady vogt

yes, can configure required ipsec , connection security policies via group policies in 1 or multiple gpos linked ou have workstations , servers requiring lan encryption using ipsec. recommended filter gpos using security groups , or wmi filters limit scope of clients , servers affected policy.

you need configure 2 different sets of policies, first policy applies servers , configure server require ipsec protection inbound connections , request ipsec protection outbound connections. second policy applies clients , configure client request ipsec protection for incoming and outgoing connections.

having mixed environment of os versions requires configuring a mix of "legacy" ipsec policies , "new" connection security policies.

please consider reading:

"windows firewall advanced security design , deployment guide" http://www.microsoft.com/download/en/details.aspx?id=17077 for windows 2008 servers , windows 7 clients

"server , domain isolation using ipsec , group policy" http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=18358 for windows xp , windoes 2003

the general microsoft landing page ipsec technologies http://www.microsoft.com/ipsec includes many useful guides , discussions implementing server , domain isolation

/hasain



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file