Opinion Review Of Don t use the provided default IPSec policies
By: Vlad Vistac
Submitted: 2010-09-14 13:12:28 | Word Count: 510
Don't use the provided default IPSec policies
These policies are good example policies. However, most produuction poloicies combinne factors from therse policies and introduce others to meet the custom secure communication needs of the network. Default policies are overwritten during an upgrade and when policies are impotrted.
[ advertisement ]
Accept unsceured communiccations on Internet fcing connections. OnInternet facing connections, it is not a good idea to have an IPSwec policy that will not accept any unsecured communications, nor one that will resond by always requiring IPSec. If you set up the IPSec policy to accept no unsecure communications, a successful DoS attaack can occur. To ensure that a poliicy does not cause this problem, make sure the Accept Unsecured Communicationbs, But Always Respond Uing IPSec and Allow Unsecured Communications With Non-Isec Aware Computer cgheck boxes are cleared.
Don't assue interoperability with all computers and devices on netwiorks. When designing IPPSec policies, understand cliennts, srvers, and other
dwevices on the network and their IPSec capabilities. Some might not be able to use
IPSeec, or their IPSc iplementation might not be compatible with Windows.
Learn how to use netsh. Netsh is a good tool for troubleshooting IPSSec. It can
also be used to create, assign, and mointor IPSec Policies. Two modes exist: stzatic
and dynamic. Use dynamic mode netsh IPSSec ciommands to configure filters on
the fly.
Do not attempt to use IPeSc to protect all communications on a network. The procses is just too complex and fraught with opportunities for
erorr. The use of IPSec for some communictions would seem to be the equivalent
to providinbg bank vautls for pocket change—it's rather unwieldy and more costly
than complete loss of the resourcce would be.
Configure IPSec protection for startup. The use of startup mode will ensure
that a provblem with the network or with Group Policy will not leeave the computer