?
Solved

IPSec is blocking network traffic

Posted on 2010-08-30
2
Medium Priority
?
1,638 Views
Last Modified: 2012-05-10
I have a windows 2003 Enterprise Edition x32 that after restarting stops responding on the network.

It is a domain controller that is also running Exchange 2003 Standard and one Virtual server instance.

The exact error message is "The ipsec driver has entered a Block mode.  IPSec will discard all inbound and outbound TCP/IP network traffic that is not permitted by boot-time IPSec Policy exemption."

One of the suggestions is to stop the IPSec services.  However I have a SSL certificate installed.

In addition to the ipsec error message there are 3 others that appear during the restart process all relating to the KDC service.

To fix the problem I simply do another restart and the server starts responding again and the error message goes away.

What on earth could be causing this?  Any suggestions would be appriciated.
ipsec-error.jpg
kdc-error.jpg
service-hang1.jpg
service-hang2.jpg
0
Comment
Question by:Douglas-Brouhard
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 2000 total points
ID: 33557788
From eventid.net extract

"As per Microsoft: "This problem occurs because the DNS Server service is listening on the UDP port that is required by another service. This problem occurs when the MaxUserPort registry entry is present. This registry entry is located in the following subkey in the registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\". See M956189 for default values for MaxUserPort. "

Read those entries, maybe they will help you

http://www.eventid.net/display.asp?eventid=4292&eventno=5676&source=IPSec&phase=1
http://www.eventid.net/display.asp?eventid=20&eventno=3396&source=KDC&phase=1
http://www.eventid.net/display.asp?eventid=7022&eventno=111&source=Service%20Control%20Manager&phase=1
http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service%20Control%20Manager&phase=1
0
 
LVL 17

Expert Comment

by:Tony Massa
ID: 33558411
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
New style of hardware planning for Microsoft Exchange server.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta‚Ķ
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates‚Ķ
Suggested Courses
Course of the Month8 days, 10 hours left to enroll

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question