PC Review


Reply
Thread Tools Rate Thread

Re: Using IPSec Filter to block Internet Access does not work from GPO (but works fine as part of local security policy)

 
 
Shant Hotoyan
Guest
Posts: n/a
 
      3rd Jul 2003
I've already tried that. I manually synced the domain to make sure all DC's
had the new GPO, then rebooted the test system. I then tried stopping and
restarting the policyagent. I even left the maching running for half a day
to see if there would be a difference after the 180 minute refresh. Nothing
changed. It receives the policy from the domain, but the contents of the
policy are not being applied.

"Louise Bowman [MSFT]" <(E-Mail Removed)> wrote in message
news:#(E-Mail Removed)...
> If the computer is a member of a domain - as it is in your case, policy
> retrieval happens when the system starts or at the defined IPSec policy
> polling interval(default 180 minutes) AD Policy.
> If you manually stop and start Policy Agent - i.e. net stop policyagent
> and net start policyagent - it should read the policy and apply it
> immediately.
>
> Louise (MSFT)
> IPSec
>
>
> --
> This posting is provided "AS IS" with no warranties, and confers no

rights.
>
>
> "Shant Hotoyan" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> > I'm trying to setup an IPSec Filter policy to block assigned systems

from
> > accessing the Internet. I've managed to create the filter lists and

> policy
> > successfully (created a policy with 2 filters, one blocks all traffic
> > to/from all addresses, and the other allows all traffic to/from all
> > addresses in our local subnet).
> >
> > If I create the filters and policy locally on a system, everything works
> > fine and the system cannot access the Internet but can access the local

> LAN.
> > However if I create the exact same filter lists and policy onto the

domain
> > and apply it through group policy, it doesn't work. GPResult shows that

> the
> > policy was applied to the system, and IPSecMon shows that IPSec is

enabled
> > on the system, but the filter lists simply do not work.
> >
> > Any ideas?
> >
> > Thank you,
> > Shant Hotoyan, MCSE, CCNP
> > Network Administrator
> > S&C Electric Canada Ltd.
> >
> >
> >

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Why "Data Access Page" cannot work in the internet website WHILE it works in the local machine Martin Microsoft Access 3 5th May 2010 08:30 AM
Logon failure and Local Security Policy fix works only before rebo =?Utf-8?B?TmlnZWwgTGVl?= Windows XP Networking 0 1st Mar 2006 07:43 AM
Re: Strange Map network drive does not work, internet works fine Chuck Windows XP Networking 1 15th Jun 2005 03:49 PM
Re: Using IPSec Filter to block Internet Access does not work from GPO (but works fine as part of local security policy) Shant Hotoyan Microsoft Windows 2000 Security 0 3rd Jul 2003 03:21 PM
Re: Using IPSec Filter to block Internet Access does not work from GPO (but works fine as part of local security policy) Shant Hotoyan Microsoft Windows 2000 Active Directory 0 3rd Jul 2003 03:21 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:38 PM.