Windows 2003 R2 IPSec Problems
I have around 60 virtual servers that I have recently enabled IPSec on. I have mainly used the default policies i.e client, request and require security, and on 3 of the more sensitive servers custom policies have been used.For the most part everything seems fine and all the systems can communicate. The problems come about in several different ways but mainly after a reboot. Once a server is rebooted it can take as long as 20 minutes to login and become responsive, in some instances I have to disable the network card to get the server to respond, after which it will be fine and IPSec works. I could understand this on servers using the require security or custom polices because of delays in communication with domain controllers etc, but even servers with just the client policy have the same issue. With IPSec disabled all servers boot and logon within 60 seconds or so.The next unusual problem is that on some servers the console will be slow to respond and launching something like SQL Server Management Studio will either just hang or take 10-20 mins to finally load, yet if I disable IPSec or disconnect the network adapter the server will spring into life and the management console will appear. If I then renable IPSec it works fine.There are no errors in the event logs, if I check the IPSec monitors it shows as having made all the relevent trusts with other servers and clients. I have also run the IPSec diagnostic tool, which comes back clean. There are also no CPU or Network performance spikes which you would expect if IPSec was struggling with filtering traffic.So far only 1 server seems to be severly affected, however this is likely to be because its a new server and the only one to have been rebooted a number of times since the implementation of IPSec. I have not seen the issue on any of the physcal servers, but again due to it being a recent implementation non of the physical servers have yet been rebooted so it maybe a problem waiting to happen.Im at a loss as to whats causing the problem, clearly its IPSec but I cant understand why, the policies seem fine, no errors etc, so at this stage I do not know if this is a windows issue or a virtualisation issue.Any help is appreciated.
February 25th, 2010 12:40am


