Windows Security
  Home arrow Windows Security arrow Page 2 - Hardening Communications
ASP Free Forums 
.NET  
ASP  
ASP Code  
ASP.NET  
ASP.NET Code  
BrainDump  
C#  
Code Examples  
Database  
Database Code  
IIS  
Microsoft Access  
MS SQL Server  
Silverlight  
Visual Basic.NET  
Windows Scripting  
Windows Security  
XML  
Mobile Linux 
App Generation ROI 
IBM® developerWorks 
ASP Web Hosting  
ASP.NET Web Hosting 
Windows Web Hosting
 
Weekly Newsletter
 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
WINDOWS SECURITY

Hardening Communications
By: McGraw-Hill/Osborne
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 5 stars5 stars5 stars5 stars5 stars / 5
    2004-10-06

    Table of Contents:
  • Hardening Communications
  • Use IPSec Policies
  • Use IPSec for Confidentiality
  • Use IPSec to Manage Connections
  • Protect IPSec-Protected Computers During Startup
  • Protect WAN Communications
  • Harden NT 4.0 Remote Access Server Configuration
  • Harden Client Access
  • Use L2TP/IPSec VPNs
  • Harden Remote Access Clients
  • Secure Wireless Access

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT


    Hardening Communications - Use IPSec Policies


    (Page 2 of 11 )

    IPSec is a security protocol built in to the Windows TCP/IP stack of Windows XP, Windows Server 2003, and Windows 2000. An IPSec policy can be configured and assigned that will protect communications by providing mutual computer authentication, encryption, integrity, protection from replay attacks, and message origination authentication. It is also widely used as a security protocol in VPNs. Its use in Windows-based VPNs is discussed in the later section “Use L2TP/IPSec VPNs.”

    Here are three major uses for IPSec in Windows LANs:

    • To provide encryption of communications between two computers

    • To manage connections on the basis of IP address and protocol used

    • To prevent connections to network resources from rogue computers

    IPSec policies are created using Group Policy. A policy can be developed and assigned to a single computer at a time using the local group policy, or configured in a GPO linked to an OU or entire domain and thus implemented on any number of computers.

    IPSec is a complex protocol, and to thoroughly understand and troubleshoot IPSec is beyond the scope of this book. A few simple facts, however, will allow you to write and use the simple policies outlined here. These facts are easier to understand by following the policy steps, but these are their basics:

    • A policy is composed of rules, filters, and filter actions.

    • Rules are composed of settings and a list of filters.

    • Filters specify source and destination IP addresses and protocols.

    • Filter actions determine what happens if a rule’s filter is matched.

    • Possible filter actions are: Block, Permit, and Negotiate. Rules are often referred to by their filter action.

    • Each rule can have only one filter action; however, a policy may be composed of one or more rules.

    • In order for Allow and Negotiate policies to work, each computer involved must have an IPSec policy assigned.

    • IPSec policies are not in effect until the policy is assigned.

    • Policies may be scripted, or the IPSec Policy Wizard can be used.

    • Three methods of authentication are available. Kerberos (only in Windows domains), certificates (all computers must have certificates and must be able to validate them), preshared key (the weakest, but good for testing).

    HEADS UP! It is possible to create an IPSec policy that can so successfully shut down communications that recovery of the computer system may be a difficult chore. To prevent complications, always test an IPSec policy in a test environment and always start by implementing the policy on one test computer at a time, then moving to a test domain.

    This is from Hardening Windows Systems, by Roberta Bragg, (McGraw-Hill/Osborne, ISBN: 0072253541). Check it out at your favorite bookstore today. Buy this book now.

    More Windows Security Articles
    More By McGraw-Hill/Osborne


     

    WINDOWS SECURITY ARTICLES

    - Which Version of Windows 7 Should You Use?
    - Choosing the Best Windows XP Firewall
    - Finding the Correct Drivers for Windows XP D...
    - Windows Network Troubleshooting: Tips and Te...
    - Windows XP Home Network Setup: Essential Ste...
    - Using Windows Recovery Console to Fix Blue S...
    - Fix Blue Screen of Death in Windows XP: Corr...
    - Storing Data with Windows Skydrive
    - Windows System Administrator`s Toolbox
    - Solving Windows Genuine Advantage Problems
    - Encrypted Browsing in Windows using OpenSSH
    - Working with the Hosts File on Windows XP
    - Inventorying HDDs Remotely on Windows
    - Inventorying RAMs Remotely on Windows
    - Vital Windows Security Guidelines





    © 2003-2009 by Developer Shed. All rights reserved. DS Cluster 2 Hosted by Hostway
    For more Enterprise Application Development news, visit eWeek