Server and Domain Isolation Using IPsec and Group Policy

Links

Published: March 17, 2005 | Updated: July 24, 2006

The following section summarizes the links to external resources that this document references. The aim of this section is to make it easier for you to add links to your own documentation.

The Antivirus Defense-in-Depth Guide
http://go.microsoft.com/fwlink/?LinkId=28732

Network Access Protection
http://go.microsoft.com/fwlink/?LinkId=69752

Microsoft Solutions Framework
http://go.microsoft.com/fwlink/?LinkId=69753

Microsoft Operations Framework
http://go.microsoft.com/fwlink/?LinkId=69755

Healthcare Without Boundaries: Integration Technology for the New Healthcare Economy
http://go.microsoft.com/fwlink/?LinkId=69757

"E-Authentication Guidance for Federal Agencies" memorandum in PDF format
http://www.whitehouse.gov/omb/memoranda/fy04/m04-04.pdf

National Information Assurance Partnership
http://www.nsa.gov/ia/industry/niap.cfm

Overview: Windows 2000 Common Criteria Certification
http://go.microsoft.com/fwlink/?LinkId=69759

FIPS 140 Evaluation
http://go.microsoft.com/fwlink/?LinkId=69761

Virtual Private Networks
http://go.microsoft.com/fwlink/?LinkId=69762

Introduction to Network Access Protection
http://go.microsoft.com/fwlink/?LinkId=69763

TechNet Security Center
http://go.microsoft.com/fwlink/?LinkId=69764

"Defense in Depth" white paper in PDF format
http://www.nsa.gov/snac/support/defenseindepth.pdf

Enterprise Design chapter of the Security Architecture Blueprint within the Windows Server System Reference Architecture
http://go.microsoft.com/fwlink/?LinkId=69765

How to Restrict the Use of Certain Cryptographic Algorithms and Protocols in Schannel.dll
http://go.microsoft.com/fwlink/?LinkId=69766

NIST Computer Security Division Web site
http://csrc.nist.gov/publications/index.html

NSA Security Recommendation Guides
http://nsa2.www.conxion.com/win2k/download.htm

Wireless Networking
http://go.microsoft.com/fwlink/?LinkId=69774

Determining Your IPSec Needs
http://go.microsoft.com/fwlink/?LinkId=69775

Securing Windows 2000 Server: Chapter 2, "Defining the Security Landscape"
http://go.microsoft.com/fwlink/?LinkId=69776

New features for IPSec
http://go.microsoft.com/fwlink/?LinkId=69777

Microsoft Systems Management Server
http://go.microsoft.com/fwlink/?LinkId=69778

L2TP/IPSec NAT-T update for Windows XP and Windows 2000
http://go.microsoft.com/fwlink/?LinkId=69779

SMS 2003 Asset Management
http://go.microsoft.com/fwlink/?LinkId=69780

Microsoft Windows Script Downloads
http://go.microsoft.com/fwlink/?LinkId=69781

IBM
http://www.ibm.com

Configuring Firewalls
http://go.microsoft.com/fwlink/?LinkId=69783

Windows Management Instrumentation (WMI) CORE 1.5 (Windows 95/98/NT 4.0) installation package
http://go.microsoft.com/fwlink/?LinkId=69782

Windows Management Instrumentation
http://go.microsoft.com/fwlink/?LinkId=69784

Microsoft Windows Script 5.6 for Windows 2000 and XP
http://go.microsoft.com/fwlink/?LinkId=69786

Microsoft Windows Script 5.6 for Windows 98, Windows Millennium Edition, and Windows NT 4.0
http://go.microsoft.com/fwlink/?LinkId=69787

Windows Script 5.6 Documentation
http://go.microsoft.com/fwlink/?LinkId=69788

Deploying Windows Firewall Settings for Microsoft Windows XP with Service Pack 2
http://go.microsoft.com/fwlink/?LinkId=23277

Improving Security with Domain Isolation
http://go.microsoft.com/fwlink/?LinkId=69789

New Resolution for Problems That Occur When Users Belong to Many Groups
http://go.microsoft.com/fwlink/?LinkId=69839

Members of an Extremely Large Number of Groups Cannot Log On to the Domain
http://go.microsoft.com/fwlink/?LinkId=69840

Using Microsoft Windows IPSec to Help Secure an Internal Corporate Network Server
http://go.microsoft.com/fwlink/?LinkId=69841

Internet Protocol Security for Windows 2000 Server
http://go.microsoft.com/fwlink/?LinkId=69842

IPsec
http://go.microsoft.com/fwlink/?LinkId=69843

Information Security at Microsoft Overview
http://go.microsoft.com/fwlink/?LinkId=69844

Windows Server 2003 Active Directory
http://go.microsoft.com/fwlink/?LinkId=69845

IPSec Default Exemptions Can Be Used to Bypass IPsec Protection in Some Scenarios
http://go.microsoft.com/fwlink/?LinkId=69846

IPSec default exemptions are removed in Windows Server 2003
http://go.microsoft.com/fwlink/?LinkId=69847

Windows XP Service Pack 2 Support Tools
http://go.microsoft.com/fwlink/?LinkId=69849

Windows 2000 Server Resource Kit
http://go.microsoft.com/fwlink/?LinkId=69965

Administering Group Policy with the GPMC
http://go.microsoft.com/fwlink/?LinkId=69850

Group Policy Management Console with Service Pack 1
http://go.microsoft.com/fwlink/?LinkId=69851

Windows Server 2003 Service Pack 1
http://go.microsoft.com/fwlink/?LinkId=41652

IPSec NAT-T is not recommended for Windows Server 2003 computers that are behind network address translators
http://go.microsoft.com/fwlink/?LinkId=69852

The default behavior of IPsec NAT traversal (NAT-T) is changed in Windows XP Service Pack 2
http://go.microsoft.com/fwlink/?LinkId=69853

Deploying Windows Firewall Settings for Microsoft Windows XP with Service Pack 2 document download
http://go.microsoft.com/fwlink/?LinkId=69966

Deploying IPsec chapter from the Windows Server 2003 Deployment Kit
http://go.microsoft.com/fwlink/?LinkId=69854

Windows Server 2003 Group Policy
http://go.microsoft.com/fwlink/?LinkId=69855

The Cable Guy—October 2004: Problems with Using Network Address Translators
http://go.microsoft.com/fwlink/?LinkId=69888

Back up System State data
http://go.microsoft.com/fwlink/?LinkId=69856

IPSec Troubleshooting Tools
http://go.microsoft.com/fwlink/?LinkId=69857

IPsec troubleshooting in Microsoft Windows 2000 Server
http://go.microsoft.com/fwlink/?LinkId=69858

Windows XP Service Pack 2 Support Tools download
http://go.microsoft.com/fwlink/?LinkId=69890

Understanding IPSec Protection During Computer Startup
http://go.microsoft.com/fwlink/?LinkId=69859

Active Directory Operations Overview: Troubleshooting Active Directory-Related DNS Problems
http://go.microsoft.com/fwlink/?LinkId=69860

HOW TO: Use Portqry to Troubleshoot Active Directory Connectivity Issues
http://go.microsoft.com/fwlink/?LinkId=69861

Troubleshooting Kerberos Errors document download
http://go.microsoft.com/fwlink/?LinkId=69862

Troubleshooting Kerberos Delegation document download
http://go.microsoft.com/fwlink?LinkID=69863

How IPsec Works
http://go.microsoft.com/fwlink/?LinkId=69864

IPSec Policy Permissions in Windows 2000 and Windows Server 2003
http://go.microsoft.com/fwlink/?LinkId=69865

Troubleshooting Translational Bridging
http://go.microsoft.com/fwlink/?LinkId=69866

How to Enable IPSec Traffic Through a Firewall
http://go.microsoft.com/fwlink/?LinkId=69867

Connections time out when client computers that are running Windows Server 2003 or Windows XP try to connect to a server on a wireless network that uses IPsec NAT-T
http://go.microsoft.com/fwlink/?LinkId=69868

White Paper: Troubleshooting Group Policy in Windows 2000
http://go.microsoft.com/fwlink/?LinkId=69869

Troubleshooting Group Policy in Microsoft Windows Server document download
http://go.microsoft.com/fwlink/?LinkId=69870

Changes to Functionality in Microsoft Windows XP Service Pack 2 - Part 2: Network Protection Technologies
http://go.microsoft.com/fwlink/?LinkId=69871

Description of the IPSec policy created for L2TP/IPSec
http://go.microsoft.com/fwlink/?LinkId=69872

How to configure an L2TP/IPSec connection by using Preshared Key Authentication
http://go.microsoft.com/fwlink/?LinkId=69873

Default MTU Size for Different Network Topology
http://go.microsoft.com/fwlink/?LinkId=69874

System Code Errors (12000-15999)
http://go.microsoft.com/fwlink/?LinkId=69875

TCP/IP in Windows 2000 Professional
http://go.microsoft.com/fwlink/?LinkId=69876

The “Troubleshooting Name Resolution and Addressing” section in the “Configuring IP Addressing and Name Resolution” chapter in the Windows XP Professional Resource Kit
http://go.microsoft.com/fwlink/?LinkId=69886

How to troubleshoot TCP/IP connectivity with Windows XP
http://go.microsoft.com/fwlink/?LinkId=69877

Windows Server 2003 TCP/IP Troubleshooting
http://go.microsoft.com/fwlink/?LinkId=69878

IPsec troubleshooting in Microsoft Windows 2000 Server
http://go.microsoft.com/fwlink/?LinkId=69879

Microsoft Windows 2000 Advanced Documentation
http://go.microsoft.com/fwlink/?LinkId=69880

Basic L2TP/IPSec Troubleshooting in Windows XP
http://go.microsoft.com/fwlink/?LinkId=69881

Microsoft Windows 2000 TCP/IP Implementation Details
http://go.microsoft.com/fwlink/?LinkId=69882

Overview of Windows 2000 Network Architecture
http://go.microsoft.com/fwlink/?LinkId=69883

How TCP/IP Works
http://go.microsoft.com/fwlink/?LinkId=69884

Special IPsec considerations
http://go.microsoft.com/fwlink/?LinkId=69885

Authentication Vulnerabilities in IKE and Xauth with Weak Pre-Shared Secrets
http://www.ima.umn.edu/~pliam/xauth

The “Configuring TCP/IP Name Resolution” section of the “Configuring IP Addressing and Name Resolution” chapter in the Windows XP Professional Resource Kit
http://go.microsoft.com/fwlink/?LinkId=69887


Top of pageTop of pagePrevious13 of 14Next
**
**