TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------


VPN negotiation with AH and ESP here produced IPUnknownProtocol Events. We
had to define Protocol 50 and 51 in the advanced propertiers of this event.
Unfortunately it is not possible to define another protocol than TCP, UDP
and ICMP in User-defined events.


-----Original Message-----
From: Steve Bernard [mailto:[EMAIL PROTECTED]] 
Sent: Dienstag, 23. Oktober 2001 15:46
To: [EMAIL PROTECTED]
Subject: RE: How to filter out protocols other than ICMP/TCP/UDP?



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Are you sure you mean IKE, as in Internet Key Exchange? IKE is used as part
of IPSec, which involves a number of protocols to negotiate and establish a
secure connection. IKE itself is based in part on ISAKMP, which uses TCP/UDP
port 500. If your IPSec implementation is using a PKI as part of its
authentication, you may also see TCP port 389 (LDAP). Depending on the type
of security negotiated, IPSec itself will use either Encapsulating Security
Payload (ESP), TCP port 50, or Authentication Header (AH), TCP port 51.

http://www.ietf.org/rfc/rfc2409.txt

Steve

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of
Tyson Garrett
Sent: Tuesday, October 23, 2001 12:21 AM
To: Mitchell, Brian (ISS Atlanta)
Cc: [EMAIL PROTECTED]
Subject: Re: How to filter out protocols other than ICMP/TCP/UDP?



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

What I'd like to be able to do is create a filter rule to ignore some
protocols other than TCP/ICMP/UDP (eg. IKE) from a point to point
perspective, eg ignore all IKE to my VPN termination point but alert me when
there is IKE somewhere else....

Cheers
Tyson




Reply via email to