How do I bypass the secpol.msc "Wizard" and set up IPsec state (esp, spi, enc, auth-trunc) and policy (src, dst, in, out, fwd) directly as in the Linux ip-xfrm command?
i had question redirected here microsoft community, although more general microsoft server:
right off bat, wizard tells me can't use multicast address, when destination i'm interested in securing. here want do--no more, no less (although may use transport mode instead of tunnel @ point):#!/bin/bash
echo 2 > /proc/sys/net/ipv4/conf/eth0/force_igmp_version
# note: avoid possibility of breaking igmpv2 snooping, src should defined senders, not receivers! otherwise, joins compromised ipsec encryption, , switch not detect them.
ip xfrm state flush; ip xfrm policy flush
ip xfrm state add src 10.0.2.15 dst 239.192.1.1 proto esp spi 0x54c1859e mode tunnel reqid 0x67cea4aa auth-trunc hmac\(sha256\) 0xc8a8bf5ce6330699c3500bd8d2637bc1fa26929bab747d5ff2a1c4dddc7ce7ff 128 enc cbc\(aes\) 0xfdce8eaf81e3da02fa67e07df975c0111ecfa906561e762e5f3e78dfe106498e # aead rfc4106\(gcm\(aes\)\) 0x123456789abcdef0baddeed0deadbeeffeedface900df00d0fedcba987654321 128 #error: duplicate "algo-type": "aead" second value.
ip xfrm policy add src 10.0.2.15 dst 239.192.1.1 dir out tmpl src 10.0.2.15 dst 239.192.1.1 proto esp reqid 0x67cea4aa mode tunnel
ip xfrm policy add src 10.0.2.15 dst 239.192.1.1 dir in tmpl src 10.0.2.15 dst 239.192.1.1 proto esp reqid 0x67cea4aa mode tunnel
ip xfrm policy add src 10.0.2.15 dst 239.192.1.1 dir fwd tmpl src 10.0.2.15 dst 239.192.1.1 proto esp reqid 0x67cea4aa mode tunnel
gui forces me work in stepwise mode (especially implement relatively simple shared-key configuration) no idea irrelevant or confusing questions lie ahead me no favors. and while particular computer uses windows 7, eventual target may use older or newer. what want create portable equivalent of privileged script, not instructions repeat tedious , confusing steps. does such avenue exist? (i checked cygwin, , there appears no support ip package, , if there were, doesn't seem support sudo either.) (note: importance of lower thought, more use android clients windows.)
hi 60srad,
i search information of the script in post, seems used create ipsec tunnel in linux, it?
since forum windows os, not familiar linux system. so, if linux, may turn linux forum better, if misunderstood, feel free let me learn.
best regards,
anne
please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.
                                                                          Windows Server                                                     >                                                                 Security                                                                           
 
 
  
 
Directly configure IPsec state and policies in Windows without secpol.msc by using advanced PowerShell scripting or registry edits. Explore DVHosting for expert solutions in network security and configuration.
ReplyDelete