|
How can I
configure an IPSec Policy through GPO?
As written
in previous articles (see related
articles at bottom of page), Windows
2000/XP/2003 machines have a built-in IP
security mechanism called IPSec (IP
Security). IPSec is a protocol that’s
designed to protect individual TCP/IP
packets traveling across your network by
using public key encryption. Besides
encryption, IPSec will also let you
protect and configure your
server/workstation with a firewall-like
mechanism.
When working on one
single computer you can easily set up
and assign IPSec Policies either from
the Command Prompt by using the NETSH
command, or from an MMC console that's
loaded with the IP Security snap-in.
However when working with
more than one computer, one might need a
better way than going through each
computer and re-configuring the IPSec
Policy. We need a method in which we can
use the same IPSec Policy on multiple
computers, or at least have the same
policy set up on a number of computers.
One method of configuring
many computers to use the same IPSec
Policy is to perform Exporting and
Importing IPSec Policies. However in
this article we will use the second
method - use of Active Directory Group
Policy Objects (or GPOs). |