Module 9: Configuring IPsec
Module 9: Configuring IPsec
Configuring IPsec
Module Overview
• Overview of IPsec
• Authentication Methods
IP HDR Data
IP HDR Data
Request Authentication for inbound and Ask that all inbound/outbound traffic be
outbound connections authenticated, but allow the connection
if authentication fails
Require authentication for inbound and Require that all inbound/outbound traffic
outbound connections be authenticated or the traffic will be
blocked
Authentication Methods
Method Key Points
Default Use the authentication method configured on the IPsec
Settings tab
Computer and User You can request or require both the user and computer
(Kerberos V5) authenticate before communications can continue; domain
membership required
Computer (Kerberos Request or require the computer to authenticate using
V5) Kerberos V5
Domain membership required
User (Kerberos V5) Request or require the user to authenticate using Kerberos
V5; domain membership required
Computer certificate • Request or require a valid computer certificate, requires at
least one CA
• Only accept health certificates: Request or require a valid
health certificate to authenticate, requires IPsec NAP
Advanced Configure any available method; you can specify methods for
First and Second Authentication
Determining a Usage Profile
Windows supports three network types, and programs can use these
locations to automatically apply the appropriate configuration options:
SHAs
NPS servers NAP agent
NAP enforcement
Non-compliant servers NAP ECs
NAP client
Certificate services
E-mail servers
NAP policy servers
Compliant NAP
client
Non-NAP Secure
capable client Remediation servers
servers
• Remediation
• Ongoing monitoring
of compliance
Health
Registration
Authority
Internet
NAP Health
DHCP Server
Perimeter Intranet Policy Server
Network
Restricted
Network
Remediation
NAP Client with
Servers
limited access
Requirements to Deploy IPsec NAP Enforcement
Active Directory
Logon information
Virtual machines NYC-DC1, NYC-CL1,
NYC-CL2
User name Administrator
Password Pa$$w0rd
• IPsec Benefits
• Tools
Notes Page Over-flow Slide. Do Not Print Slide.
See Notes pane.
Notes Page Over-flow Slide. Do Not Print Slide.
See Notes pane.