TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ----------------------------------------------------------------------------
VPN negotiation with AH and ESP here produced IPUnknownProtocol Events. We had to define Protocol 50 and 51 in the advanced propertiers of this event. Unfortunately it is not possible to define another protocol than TCP, UDP and ICMP in User-defined events. -----Original Message----- From: Steve Bernard [mailto:[EMAIL PROTECTED]] Sent: Dienstag, 23. Oktober 2001 15:46 To: [EMAIL PROTECTED] Subject: RE: How to filter out protocols other than ICMP/TCP/UDP? TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ---------------------------------------------------------------------------- Are you sure you mean IKE, as in Internet Key Exchange? IKE is used as part of IPSec, which involves a number of protocols to negotiate and establish a secure connection. IKE itself is based in part on ISAKMP, which uses TCP/UDP port 500. If your IPSec implementation is using a PKI as part of its authentication, you may also see TCP port 389 (LDAP). Depending on the type of security negotiated, IPSec itself will use either Encapsulating Security Payload (ESP), TCP port 50, or Authentication Header (AH), TCP port 51. http://www.ietf.org/rfc/rfc2409.txt Steve -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Tyson Garrett Sent: Tuesday, October 23, 2001 12:21 AM To: Mitchell, Brian (ISS Atlanta) Cc: [EMAIL PROTECTED] Subject: Re: How to filter out protocols other than ICMP/TCP/UDP? TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ---------------------------------------------------------------------------- What I'd like to be able to do is create a filter rule to ignore some protocols other than TCP/ICMP/UDP (eg. IKE) from a point to point perspective, eg ignore all IKE to my VPN termination point but alert me when there is IKE somewhere else.... Cheers Tyson
