TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ----------------------------------------------------------------------------
"NGHE/NG, K.M. HENRY (IT-ISD-OOCL/HKG)" wrote: > TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to > [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! > ---------------------------------------------------------------------------- > > Are you sure that ESP and AH are TCP protocol? It seems that they are > protocols themselves, not TCP protocol with different port numbers. > > Regards, > Henry Ng > > -----Original Message----- > From: Steve Bernard [mailto:[EMAIL PROTECTED]] > Sent: Tuesday, October 23, 2001 9:46 PM > To: [EMAIL PROTECTED] > Subject: RE: How to filter out protocols other than ICMP/TCP/UDP? > > TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to > [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any > problems! > ---------------------------------------------------------------------------- > > Are you sure you mean IKE, as in Internet Key Exchange? IKE is used as part > of IPSec, which involves a number of protocols to negotiate and establish a > secure connection. IKE itself is based in part on ISAKMP, which uses TCP/UDP > port 500. If your IPSec implementation is using a PKI as part of its > authentication, you may also see TCP port 389 (LDAP). Depending on the type > of security negotiated, IPSec itself will use either Encapsulating Security > Payload (ESP), TCP port 50, or Authentication Header (AH), TCP port 51. > > http://www.ietf.org/rfc/rfc2409.txt > > Steve > > -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of > Tyson Garrett > Sent: Tuesday, October 23, 2001 12:21 AM > To: Mitchell, Brian (ISS Atlanta) > Cc: [EMAIL PROTECTED] > Subject: Re: How to filter out protocols other than ICMP/TCP/UDP? > > TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to > [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any > problems! > ---------------------------------------------------------------------------- > > What I'd like to be able to do is create a filter rule to ignore some > protocols other than TCP/ICMP/UDP (eg. IKE) from a point to point > perspective, eg ignore all IKE to my VPN termination point but alert me > when there is IKE somewhere else.... > > Cheers > Tyson They are actually at the network layer as you say, they are themselves protocols.
