K
kjelle
Cenario:
Mixed environment with Windows 2000 and 2003 servers and
clients.
IPSEC policys is distributed to clients and servers on
the network through group policys to protect
the "IPSEC_Users" OU´s communication on all IPtraffic.
Secured users and clients using ipsec is placed in a OU
called "IPSEC_users".
Domain controllers are placed in default OU "Domain
Controllers".
Secured servers are placed in a OU called "IPSEC_servers".
Using the default ipsec policy filters in Windows the
computers in "IPSEC_users" OU is assigned the "Request
security" filter with certificate authentication on all
IPtraffic.
The "Domain Controller" OU is assigned "Respond only"
filter with certificate authentication on all IPtraffic.
The "IPSEC_servers" OU is assigned "Require security"
filter with certificate authentication on all IPtraffic.
Problem:
The problem arrise when the clients and domain
controllers are using these settings. The ipsec
kommunication works after a cashed login but the big
thing is that the client cannot locate the domain
controller in the domain for authentication at logon
witch result in group policy not beeing assigned. The
error message in event viewer is:
Event id 1054: Can´t read the domain controller name on
the network. The specified domain is not available or
could not be contacted.............
AND
Event id 5719: This computer could not establish a secure
session with a domain controller in this domain LABB
because of following error:
There are no logon servers available to handle the login
request.........
I doesn´t matter what kind of authentication method is
used, kerberos, pre-shared key or certificate
authentication.
I have been running a packet capture program on the
domain controller and analyzed what kind of traffic is
sent when the client is trying to login. I can clearly
see that the client is trying to do a DNS loockup of the
SRV record for the domain controller although there is no
reply sent from the server.
Although I manually add a filter action to send DNS
traffic in clear text between client and server, the
server doesn´t reply. I think this is the reason to why
the client can´t login correctly and maintain the policy
settings.
The question is why this occur?
Best regards
Kjelle
Mixed environment with Windows 2000 and 2003 servers and
clients.
IPSEC policys is distributed to clients and servers on
the network through group policys to protect
the "IPSEC_Users" OU´s communication on all IPtraffic.
Secured users and clients using ipsec is placed in a OU
called "IPSEC_users".
Domain controllers are placed in default OU "Domain
Controllers".
Secured servers are placed in a OU called "IPSEC_servers".
Using the default ipsec policy filters in Windows the
computers in "IPSEC_users" OU is assigned the "Request
security" filter with certificate authentication on all
IPtraffic.
The "Domain Controller" OU is assigned "Respond only"
filter with certificate authentication on all IPtraffic.
The "IPSEC_servers" OU is assigned "Require security"
filter with certificate authentication on all IPtraffic.
Problem:
The problem arrise when the clients and domain
controllers are using these settings. The ipsec
kommunication works after a cashed login but the big
thing is that the client cannot locate the domain
controller in the domain for authentication at logon
witch result in group policy not beeing assigned. The
error message in event viewer is:
Event id 1054: Can´t read the domain controller name on
the network. The specified domain is not available or
could not be contacted.............
AND
Event id 5719: This computer could not establish a secure
session with a domain controller in this domain LABB
because of following error:
There are no logon servers available to handle the login
request.........
I doesn´t matter what kind of authentication method is
used, kerberos, pre-shared key or certificate
authentication.
I have been running a packet capture program on the
domain controller and analyzed what kind of traffic is
sent when the client is trying to login. I can clearly
see that the client is trying to do a DNS loockup of the
SRV record for the domain controller although there is no
reply sent from the server.
Although I manually add a filter action to send DNS
traffic in clear text between client and server, the
server doesn´t reply. I think this is the reason to why
the client can´t login correctly and maintain the policy
settings.
The question is why this occur?
Best regards
Kjelle