Deploying IPsec Enforcement

The deployment of IPsec enforcement consists of the following tasks:

  • Configuring Active Directory

  • Configuring PKI

  • Configuring HRAs

  • Configuring NAP health policy servers

  • Configuring remediation servers on the boundary network

  • Configuring NAP clients

  • Configuring and applying IPsec policies

Configuring Active Directory

To configure Active Directory for IPsec enforcement, do the following:

  • Add an IPsec exemption group for computers in the boundary network.

  • Create groups or OUs for boundary and secure network computers.

To Add an IPsec Exemption Group

  1. In the console tree of the Active Directory Users And Computers snap-in, right-click your domain name, point to New, and then click Group.

  2. In the Group Name box, type the name (such as ...

Get Windows Server® 2008 Networking and Network Access Protection (NAP) now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.