IPSEC through firewall for DC replication

T

tony

ALL,

I am trying to use IPSEC to send Domain Controller
replication through the firewall for a one-way trust with
the Domain controllers in the DMZ. However, IPSec (ESP)
packet dropped keeps occuring at the firewall because the
destination port is being randomly assigned, the source
port for IPSEC(ESP) is port 0. Is there a way to force
the destination port to a specific port number so I can
allow it in my firewall rules?

Thank you,

Tony
 
S

Steven L Umbach

ESP uses "protocol 50" as described in the KB below. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;233256

IPSec does not disturb the original IP header and can be routed as normal IP traffic.
Routers and switches in the data path between the communicating hosts simply forward
the packets to their destination. However, when there is a firewall or gateway in the
data path, IP forwarding must be enabled at the firewall for the following IP
protocols and UDP ports:
a.. IP Protocol ID 50:
For both inbound and outbound filters. Should be set to allow Encapsulating
Security Protocol (ESP) traffic to be forwarded.
b.. IP Protocol ID 51:
For both inbound and outbound filters. Should be set to allow Authentication Header
(AH) traffic to be forwarded.
c.. UDP Port 500:
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top