IPSEC rules and filters


i'm looking way add large numbers subnets ipsec rule.
want setup group of ip subnets in filter e.g. china , block ip's

ipseccmd gives me 100 before line long i'm looking in order of 1000's of subnets.
if run command second time old filters removed , new ones added ca't append them running multiple times.

there  way can this?

if create large ban list run in order of 10,000 subnets have significant impact on performance? assume ip lookup rapid operation when in numeric form. have database on 100,000 don't want have build own packet filter if can avoid it.

hi,

if have windows server 2008 or windows vista, may try "netsh advfirewall firewall". reference:

how use "netsh advfirewall firewall" context instead of "netsh firewall" context control windows firewall behavior in windows server 2008 , in windows vista
http://support.microsoft.com/kb/947709

if you’re using windows xp or windows server 2003, can try  netsh firewall.
netsh command syntax netsh firewall context
http://technet.microsoft.com/en-us/library/bb490617.aspx

thanks.

this posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group