Article ID: 313236 - Last Review: October 30, 2006 - Revision: 2.1 HOW TO: Clear Existing IPSec Security Associations in Windows 2000This article was previously published under Q313236 On This PageSUMMARY
When you troubleshoot Internet Protocol security (IPSec) configuration problems, you may have to clear existing security associations. For example, you may have to clear existing IPSec security associations in any of the following situations:
A soft security association tells the IPSec drive not to use security between the two Internet Protocol (IP) addresses. In this situation, unsecured packets are exchanged by the participants. If you modify the existing IPSec policy and you do not break the extant soft association, no packets are secured across the connection. You can create soft security associations by using both IPSec-aware and non-IPSec-aware computers. To clear existing IPSec security associations, restart the IPSec Policy Agent service. IPSec Policy Agent retrieves IPSec policy information and passes it to the other IPSec policy mechanisms. IPSec Policy Agent is a service that exists on all Windows 2000-based computers. The service retrieves the appropriate IPSec policy from Active Directory or the local security policy. After the policy is retrieved, IPSec Policy Agent sends it to the IPSec driver. How to Clear Existing IPSec Security Associations by Using a Command Prompt
How to Clear Existing IPSec Security Associations by Using the GUITo use the graphical user interface (GUI) to clear existing security associations:
| Article Translations
|
Back to the top
