Link to home
Start Free TrialLog in
Avatar of compdigit44
compdigit44

asked on

Windows 2012 R2 IPSec and Windows Firewall

In Windows 2012 R2 we have setup and assigned a IPSEC policy. IN the policy we did not specify an endpoint on the initial screen since the IPSec tunnel is between two internal servers. My questions is it is required to have the firewall enabled and have a rule setup to force all inbound or outbound connections through IPSec? I guess what I am asking is  will IPSec work if the Windows firewall is disabled? Right now we are trying to test the IPSec tunnel between the two servers and only see Key deletions listed under the IPSec Stats everything else is zero and nothing listed under associations.
ASKER CERTIFIED SOLUTION
Avatar of noci
noci

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of compdigit44
compdigit44

ASKER

Thank you very much there is a firewall between the server and I have been working with our Network team on. Protocol ID 50, 51 and UDP 88 are allowed. In IPSEC Monitor I am seeing traffic sending but nothing received. Plus I see nothing under associations. I even tried to un-assign the IPSec policy on all servers involved and still cannot ping even though the network firewall is allowing it. Now we are not Nat'ing and did not request port 4500. Also the windows firewall is disable just to take this out of the loop. Are their any other ports I am missing?