IPSEC policies in Windows 2008 R2
Hi
I have configured an ipsec isolation policy on one server that requires authentication for inbound traffic ( any protocol) using kerberos (computer) .
Now, all machines not member of the domain cannot access the server and only joined machines can access it.
The thing is , from a domain join machine, i canot ping it ! i can access it using anyother protocol except ping. If i disable the IPSEC rule, the Ping comes back ! any clue?ammarhasayen
March 20th, 2011 5:26pm
Have you tried setting up a specific allow rule for ICMP?
Brian
Free Windows Admin Tool Kit Click here and download it now
March 20th, 2011 11:33pm
If i set another rule that request authentication for inbound and outbound for ICMP 4 and ping is back to normal.
My question is why my computer (domain joined) is not able to authenticate using computer kerberos to ICMB traffic?ammarhasayen
March 21st, 2011 3:50am
I find that ICMP typically needs its own rule (more of a stateless protocol)
When you added the separate rule for inbound and outbound IPSec it worked, right?
Brian
Free Windows Admin Tool Kit Click here and download it now
March 21st, 2011 8:03am
Yes Thanks Brian .. You are always helpful :)ammarhasayen
March 21st, 2011 11:03am


