MS OS - Microsoft Forum to Usenet Gateway Header Right
Navbar Left Navbar Right


I have a bunch of servers in my environment that have IPSec enabled but not configured; some of theose servers are having serious performance issues, but if I stop and



Reply
Old 08-27-2008, 02:38 PM   #1
Tim
Guest
 
Posts: n/a
Default When is it OK to disable IPSec on windows 2003?

I have a bunch of servers in my environment that have IPSec enabled but not
configured; some of theose servers are having serious performance issues, but
if I stop and disable the IPSec service, the performance issues go away. I
have read some articles that say that IPSec should only be enabled if it's
going to be configured, but I'm not that familiar with IPSec. I have two
questions:

1. Is the statement that IPSec should only be enabled if it's going to be
configured and used a valid statement?

2. What's the easiest way - besides opening the IPSec Snap-In on every
server and checking for policies - to know whether or not a server is
actually using IPSec policies?


Thanks in advance for your help!
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-28-2008, 04:45 AM   #2
S. Pidgorny
Guest
 
Posts: n/a
Default Re: When is it OK to disable IPSec on windows 2003?

G'day,

The answers: no, and by creating IPsec policy in a GPO applying to all
servers.

To elaborate on the answer to the #1: do nothing is viable and
attractive option in your case. Only change defaults if you have good
reasons to do so.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

Tim wrote:
> I have a bunch of servers in my environment that have IPSec enabled but not
> configured; some of theose servers are having serious performance issues, but
> if I stop and disable the IPSec service, the performance issues go away. I
> have read some articles that say that IPSec should only be enabled if it's
> going to be configured, but I'm not that familiar with IPSec. I have two
> questions:
>
> 1. Is the statement that IPSec should only be enabled if it's going to be
> configured and used a valid statement?
>
> 2. What's the easiest way - besides opening the IPSec Snap-In on every
> server and checking for policies - to know whether or not a server is
> actually using IPSec policies?
>
>
> Thanks in advance for your help!


 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 08-28-2008, 07:44 AM   #3
Tim
Guest
 
Posts: n/a
Default Re: When is it OK to disable IPSec on windows 2003?

Thanks for responding so quickly, but your answers left me with a few more
questions. For example, I'm not sure why I would create an IPSec policy I
don't plan to use. Second, how is doing nothing an attractive option when
we're taking a performance hit because of it? Also, I've read that IPSec is
supposed to be disabled by default; is that not the case and, if it is,
shouldn't I disable it until or unless I need it? I'm not trying to be
difficult; I just need to understand this stuff better. Thanks again.



"S. Pidgorny <MVP>" wrote:

> G'day,
>
> The answers: no, and by creating IPsec policy in a GPO applying to all
> servers.
>
> To elaborate on the answer to the #1: do nothing is viable and
> attractive option in your case. Only change defaults if you have good
> reasons to do so.
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
> Tim wrote:
> > I have a bunch of servers in my environment that have IPSec enabled but not
> > configured; some of theose servers are having serious performance issues, but
> > if I stop and disable the IPSec service, the performance issues go away. I
> > have read some articles that say that IPSec should only be enabled if it's
> > going to be configured, but I'm not that familiar with IPSec. I have two
> > questions:
> >
> > 1. Is the statement that IPSec should only be enabled if it's going to be
> > configured and used a valid statement?
> >
> > 2. What's the easiest way - besides opening the IPSec Snap-In on every
> > server and checking for policies - to know whether or not a server is
> > actually using IPSec policies?
> >
> >
> > Thanks in advance for your help!

>
>

 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
windows 2003 server group policy setting to disable windows systemsounds?? EJ Windows 2003 Server 1 03-28-2008 08:01 AM
Cannot disable network browsing using Win 2008 TS and a Win 2003 A E.F.A. Windows NT Server 0 03-17-2008 11:33 PM
Why Disable Lock Computer on Windows 2003 TS James Windows NT Server 4 12-12-2007 04:52 PM
Disable Server 2003 shutdown reason... Cartoper Windows 2003 Server 1 12-02-2007 11:14 PM
Domain Isolation and non-windows IPSec capable systems Andrea Casini Windows Security 1 09-05-2007 03:12 PM


All times are GMT -5. The time now is 04:35 PM.


Powered by vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Skin designed by CompletevB
Copyright © 2005-2008 Robert Schwarz, Sr. - All rights reserved - MS OS is an independent web site and is not affiliated with Microsoft Corporation.