<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory Replication over Firewalls in Windows Server 2003</title>
    <link>https://community.hpe.com/t5/windows-server-2003/active-directory-replication-over-firewalls/m-p/3845464#M3489</link>
    <description>IPSec protected traffic will not work with Network Address Translation (NAT). NAT needs to modify packets in transit, but IPSec is designed to be tamper resistant, preventing packet modification. The IETF is currently working toward specifying a NAT and IPSec interoperability standard.&lt;BR /&gt;&lt;BR /&gt;A new technology known as IPsec NAT Traversal (NAT-T) has been standardized by the IP Security Protocol Working Group of the Internet Engineering Task Force (IETF) and is defined in Requests for Comments (RFCs) 3947 and 3948. IPsec NAT-T defines both changes in the negotiation process and different methods of sending IPsec-protected data.&lt;BR /&gt;&lt;BR /&gt;Information about NAT-T can be found here:&lt;BR /&gt;&lt;A href="http://www.microsoft.com/technet/community/columns/cableguy/cg0802.mspx" target="_blank"&gt;http://www.microsoft.com/technet/community/columns/cableguy/cg0802.mspx&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Another good document for AD with IPSEC and protected networks:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c2ef3846-43f0-4caf-9767-a9166368434e&amp;amp;DisplayLang=en" target="_blank"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=c2ef3846-43f0-4caf-9767-a9166368434e&amp;amp;DisplayLang=en&lt;/A&gt;</description>
    <pubDate>Thu, 17 Aug 2006 14:00:41 GMT</pubDate>
    <dc:creator>Ivan Ferreira</dc:creator>
    <dc:date>2006-08-17T14:00:41Z</dc:date>
    <item>
      <title>Active Directory Replication over Firewalls</title>
      <link>https://community.hpe.com/t5/windows-server-2003/active-directory-replication-over-firewalls/m-p/3845463#M3488</link>
      <description>We're trying to enable Active Directory replication between 2 sites divided by 2 separate firewalls using NAT.&lt;BR /&gt;&lt;BR /&gt;The Setup&lt;BR /&gt;&lt;BR /&gt;Private: 192.168.255.#&lt;BR /&gt;Public: 62.49.#.#&lt;BR /&gt;Domain Controller (Windows 2003)&lt;BR /&gt;  |&lt;BR /&gt;  |&lt;BR /&gt;  |&lt;BR /&gt;3Com OfficeConnect VPN firewall (3CR870-95)&lt;BR /&gt;1-to-1 NAT Enabled&lt;BR /&gt;  |&lt;BR /&gt;  |&lt;BR /&gt;[Internet]&lt;BR /&gt;  |&lt;BR /&gt;  |&lt;BR /&gt;Cisco PIX 515E&lt;BR /&gt;1-to-1 NAT Enabled&lt;BR /&gt;  |&lt;BR /&gt;  |&lt;BR /&gt;  |&lt;BR /&gt;Private: 192.168.84.#&lt;BR /&gt;Public: 212.78.#.#&lt;BR /&gt;Domain Controller (Windows 2003)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The question&lt;BR /&gt;&lt;BR /&gt;Can we utilise IPSec for Active Directory replication (using Kerberos for authentication). If yes, could someone point me in the direction of documentation that explains how to achieve this or provide some pointers. I've followed several Microsoft articles including the well written one by Steve Riley (Active Directory Replication over Firewalls) but so far I've been unable to get replication working. When doing a ping it continuously responds with "Negotiating IP security". When setting up the IPSec IP filter, do I specify the private IP address of the destination server or the public IP address?&lt;BR /&gt;</description>
      <pubDate>Thu, 17 Aug 2006 10:53:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/active-directory-replication-over-firewalls/m-p/3845463#M3488</guid>
      <dc:creator>Neil Rudd</dc:creator>
      <dc:date>2006-08-17T10:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Replication over Firewalls</title>
      <link>https://community.hpe.com/t5/windows-server-2003/active-directory-replication-over-firewalls/m-p/3845464#M3489</link>
      <description>IPSec protected traffic will not work with Network Address Translation (NAT). NAT needs to modify packets in transit, but IPSec is designed to be tamper resistant, preventing packet modification. The IETF is currently working toward specifying a NAT and IPSec interoperability standard.&lt;BR /&gt;&lt;BR /&gt;A new technology known as IPsec NAT Traversal (NAT-T) has been standardized by the IP Security Protocol Working Group of the Internet Engineering Task Force (IETF) and is defined in Requests for Comments (RFCs) 3947 and 3948. IPsec NAT-T defines both changes in the negotiation process and different methods of sending IPsec-protected data.&lt;BR /&gt;&lt;BR /&gt;Information about NAT-T can be found here:&lt;BR /&gt;&lt;A href="http://www.microsoft.com/technet/community/columns/cableguy/cg0802.mspx" target="_blank"&gt;http://www.microsoft.com/technet/community/columns/cableguy/cg0802.mspx&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Another good document for AD with IPSEC and protected networks:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c2ef3846-43f0-4caf-9767-a9166368434e&amp;amp;DisplayLang=en" target="_blank"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=c2ef3846-43f0-4caf-9767-a9166368434e&amp;amp;DisplayLang=en&lt;/A&gt;</description>
      <pubDate>Thu, 17 Aug 2006 14:00:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/windows-server-2003/active-directory-replication-over-firewalls/m-p/3845464#M3489</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-08-17T14:00:41Z</dc:date>
    </item>
  </channel>
</rss>

