Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Do IPSec Filters update with background Group Policy Refresh in 2008 R2/Windows 7?

$
0
0
Background:  I am migrating a secure 2003/XP environment to 2008 R2/Windows 7.  I use domain based IP Security throughout the environment with an entry per device.  So each time I add a device or change an IP address, an IP Security Filter is updated.  In 2003/XP, the filter list changes propagate throughout the domain during background refresh of Group Policy, or during the specified interval on the IP Security Policy, whichever comes first. 

The problem I'm having is when I modify a filter list, the changes don't propagate to any of the 2008 R2/Windows 7 machines on the network unless they are rebooted, or I run a gpupdate /force on them.  Another symptom is in the IP Security Monitor snap-in, the "Policy Last Modified" and "Description" fields are blank, but with the same IPSec policy applied to a 2003/XP machine, everything works as advertised and those fields are populated.

I know IPSec is intended to be managed via Windows Firewall with Advanced Security in Vista and up, but the IP Security Policy Manager and IP Security Monitor snap-ins were provided for backwards compatibility and I would love to use this to my advantage while migrating.

Google doesn't seem to know much on this topic, I'm guessing because not many people use IPSec, and those who do don't typically use it like I described above.

Many thanks for any insight offered.

Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>