When you automate the installation of Windows 2000 using the unattended
installation method, you are unable to configure the Transport Control Protocol/Internet Protocol (TCP/IP) Internet Protocol security (IPSec) settings.
This section describes how to install IPSec and provides other related information.
NOTE: Before you configure IPSec to be used for communication between computers, you must test basic TCP/IP connectivity between the computers with a tool such as Ping.exe. Basic TCP/IP connectivity must be functioning before IPSec can be successfully implemented.
Add the IPSec Snap-in to the MMC:
Click Start, click Run, type mmc.exe, and then press ENTER.
Add IP Security Policy Management to the console, and then select Local Computer when prompted.
Create an IPSec Policy
In the right pane, right-click IP Security Policy on Local Machine, click Create IP Security Policy, and then press ENTER.
Enter a policy name, and then press ENTER.
Accept the default settings for the Requests for Secure Connection screen by leaving the default response rule check box checked, and then click Next.
Accept the default response rule for Kerberos authentication, and then click Next.
Make sure the Edit Properties check box is checked, and if it is not, click to select it.
Click Finish. The properties box appears, do not close it.
Add a New Rule
At the bottom of the Properties dialog box, click to clear the Use Add Wizard check box.
On the Rules tab of the Properties dialog box, click Add. The New Rule Properties dialog box appears.
Add a Filter to the Rule
Click Add, and then enter a filter name.
Click to clear the Use Add Wizard check box.
On the IP Filter List tab, click Add.
In the Filter Properties box, change the Source Address to Specific IP Address, and then add the IP address of your computer.
Change Destination Address to Specific IP Address, and then add the IP address of the destination computer.
Click OK, verify that your filter has been added in the filters box of the IP Filter List dialog box, and then click Close.
On the IP Filter List tab, activate the filter by clicking the option next to the filter list you just added.
Specify a Filter Action for the Rule
Click the Filter Action tab, and then click to clear the Use Add Wizard check box.
Click Add to create a filter action.
On the Security Methods tab, ensure that Negotiate Security is selected.
Verify that Allow Unsecured Communication with Non IPSec Aware Computer is not selected.
Click Add to choose a security method.
Select Medium (AH), and then click OK.
Click OK to close the new Filter Action properties.
To activate the filter, click the option next to the filter you just created.
Set the Authentication Method
Click the Authentication Method tab, click Add, and then click Pre-shared Key.
Type a pre-shared password key in the text box, and then click OK.
Choose Pre-shared Key in the list, and then click Move Up so it appears first in the list.
Click the Tunnel Settings tab, and verify that This rule does not specify an IPSec tunnel is selected.
Click the Connection Type tab, and verify that All Network Connections is selected.
Click Close, and verify that this new rule is selected in the list box.
In the right pane of the MMC, right-click the policy name you just created, and then click Assign. The Policy Assigned column value should now be YES.
Enable the IP security policy on both computers.
For additional information about IP security, click the article number below
to view the article in the Microsoft Knowledge Base:
231585
(http://support.microsoft.com/kb/231585/EN-US/
)
Overview of Secure IP Communication with IPSec in Windows 2000