Welcome to the { mindfrost82.com } forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-02-2008, 11:47 AM
Scott
 
Posts: n/a
IP Security Policies wont all DNS 53 pass through ?

Hi,

On Windows 2003 64 bit server i run the following test

telnet <dns ip> 53
i connect ok to a remote dns server.

I created a PACKET FILTER policy.
Within this policy i have created the RULE "DNS".
Within this rule i have a DNS filter.

Filter is setup as follows:
source = any ipaddress
destination = any ip address
protocol = tcp
from = any
to = 53
saved/applyed

I now assigned the policy and try
telnet <dns ip> 53

It fails to connect to the remote DNS server.

If i unasigned the policy it works again.

Why does my policy fail to allow DNS to pass through ?

(Have used gpudate to flush just incase but ASSIGN then UNASSIGN clearly
shows the 2 states failing / working).

Thanks for any advice.
Scott


Reply With Quote
  #2 (permalink)  
Old 05-02-2008, 10:52 PM
Herb Martin
 
Posts: n/a
Re: IP Security Policies wont all DNS 53 pass through ?


"Scott" <scott_lotus@yahoo.co.uk> wrote in message
news:ObVa%23HErIHA.1772@TK2MSFTNGP03.phx.gbl...
> Hi,
>
> On Windows 2003 64 bit server i run the following test
>
> telnet <dns ip> 53
> i connect ok to a remote dns server.


Do note that telnet is a TCP (only) utility and that DNS
resolution is mostly UDP.

NetCat (free on the Internet) is a much better tool for
non-TCP services and even for TCP stuff too.

> I created a PACKET FILTER policy.
> Within this policy i have created the RULE "DNS".
> Within this rule i have a DNS filter.
>
> Filter is setup as follows:
> source = any ipaddress
> destination = any ip address
> protocol = tcp
> from = any
> to = 53
> saved/applyed
>
> I now assigned the policy and try
> telnet <dns ip> 53


Are these RRAS filters or IPSec? Are you allowing, deny,
or (for IPSec only) negotiating IPSec?

> It fails to connect to the remote DNS server.
>
> If i unasigned the policy it works again.
> Why does my policy fail to allow DNS to pass through ?


Did you build an IPSec policy yourself, use Kerberos as the
authentication method, and block Kerberos perhaps?

(The default policies all use Kerberos authentication AND
exempt Kerberos from the IPSec requirement.)

> (Have used gpudate to flush just incase but ASSIGN then UNASSIGN clearly
> shows the 2 states failing / working).


IPSecMon might be of use. Turn on Account Logon auditing and
monitor authentication when you are working with Kerberos
authenticated IPSec.



Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:00 PM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0


Sponsors:
Online Dating | Loan | Credit Cards | Online Loans | Credit Cards



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114