Microsoft Help Forums: Ping and IPSec AuthIP user authentication - Microsoft Help Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Ping and IPSec AuthIP user authentication Rate Topic: -----

#1
Beth Swathmore

  • Group: Guests
Hello:

It appears on Server 2008-R2 and Windows 7 that you cannot require IPSec
user authentication for inbound ICMPv4 echo requests (pings) without causing
those ping requests to be dropped.

In my testing, you can of course require IPSec for pings, you can also
require computer authentication from the pinging peer in the forest and
it'll still work fine, but once you add IPSec user authentication (with or
without computer auth too), then the incoming ping packets are dropped.
Yes, I've got IPSec user authentication correctly configured and working
with other protocols on the same test boxes (Kerberos for computer auth,
Kerberos for user auth), but it seems ping does not work with IPSec user
authentication. On my test systems, ICMP is not exempted. Testing was done
with the built-in ICMPv4-In incoming firewall rule in the "File and Printer
Sharing" group. No testing done with ICMPv6.

Has this been the experience of others too?

Thx




0

#2
Peter Foldes

  • Group: Guests
Beth

Wrong newsgroup . What you want is the windows.server.security newsgroup as per
below

news://msnews.micros...server.security


--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"Beth Swathmore" <bswathm@fizzle.com> wrote in message
news:udpgd0BrKHA.5940@TK2MSFTNGP02.phx.gbl...
> Hello:
>
> It appears on Server 2008-R2 and Windows 7 that you cannot require IPSec user
> authentication for inbound ICMPv4 echo requests (pings) without causing those ping
> requests to be dropped.
>
> In my testing, you can of course require IPSec for pings, you can also require
> computer authentication from the pinging peer in the forest and it'll still work
> fine, but once you add IPSec user authentication (with or without computer auth
> too), then the incoming ping packets are dropped. Yes, I've got IPSec user
> authentication correctly configured and working with other protocols on the same
> test boxes (Kerberos for computer auth, Kerberos for user auth), but it seems ping
> does not work with IPSec user authentication. On my test systems, ICMP is not
> exempted. Testing was done with the built-in ICMPv4-In incoming firewall rule in
> the "File and Printer Sharing" group. No testing done with ICMPv6.
>
> Has this been the experience of others too?
>
> Thx
>
>
>



0

#3
Beth Swathmore

  • Group: Guests
> Wrong newsgroup . What you want is the windows.server.security newsgroup\

Thanks!




0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users