Home > Ask the Security Experts > Platform Security Questions & Answers > How should the ipseccmd.exe tool be used in Windows Vista?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How should the ipseccmd.exe tool be used in Windows Vista?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 01 November 2007
How should the ipseccmd.exe tool be used in Windows Vista?

>
Ipseccmd is a command-line tool for displaying and managing IPsec policy and filtering rules. If you type ipseccmd show all at a Windows XP command prompt, you will get a list of Internet Key Exchange Security Associations, IPsec filters and IPsec usage statistics. It is, however, a Windows XP tool, and it is not available in Windows Vista. This functionality has moved to Netsh, a command-line scripting utility.

Netsh uses various helper DLLs, which provide an extensive set of network configuration and monitoring settings. Each group of commands specific to a networking component is called a context. For example, dhcpmon.dll provides Netsh the context and set of commands necessary to configure and manage DHCP servers. The contexts that you can use depend on which networking components you have installed.

Netsh can run in either a wired or wireless context as well; when using the tool, the user must change to the context that contains the desired command. Both contexts allow viewing and configuring connectivity and security settings of both the local and multiple computers, but to view the applied wireless Group Policy settings, for example, the wireless context must be used. For those comfortable with command-line tools, Netsh is a good, lightweight alternative to Group Policy. The help documentation for each available command is reached by the '/?' or Help options.

Vista itself has two new Netsh contexts, which I'm sure you'll find useful:

  • ipsec - this context is most comparable to policy creation in XP.
  • advfirewall - this context maps to the Windows Firewall with Advanced Security snap-in.

One definite improvement in Vista is the integration of firewall-filtering functions and IPsec protection settings. The design makes it far less likely that new firewall filters will conflict with IPsec policies and prevent network traffic from flowing as intended. It is now possible to confirm, add, modify and delete firewall rules using Windows Firewall with Advanced Security. While most users will still configure their Windows Firewall using the Windows Firewall Control Panel tool, the snap-in allows users to easily perform advanced configuration. Windows Firewall with Advanced Security provides a GUI interface for configuring Windows Firewall on remote computers and via Group Policy.

I know that some administrators have had problems trying to get scripts that previously used ipseccmd functions to then work on Vista using Netsh. That aside, the new Vista tools do make it easier to control what enters and exits your network PCs, so give them a go.

More information:
  • Ed Skoudis explains how to use the command line to find malware on your Windows box.
  • Learn more about intrusion defense in the era of Windows Vista.


  • BROWSE BY TAG
    Platform Security,   Application and Platform Security,   Windows Security: Alerts, Updates and Best Practices,   Operating System Security,   IPsec VPN Security,   Secure VPN Setup and Configuration,   Enterprise Network Security,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Platform Security
    What patch management metrics does Project Quant use?
    Should developers create libraries of common cryptographic algorithms?
    How to secure USB ports on Windows machines
    What is the best database patch management process?
    What is an encryption collision?
    What are new and commonly used public-key cryptography algorithms?
    Should management processes change based on a patch release schedule?
    Does an EULA make it truly illegal to decompile software?
    Should businesses delay Windows Vista adoption and just buy Windows 7?
    Why should we place data files on a separate partition than the OS?

    Windows Security: Alerts, Updates and Best Practices
    Exploit code targets Internet Explorer zero-day display flaw
    Windows 7 DoS flaw allows hackers to freeze Microsoft's newest OS
    Microsoft patches serious Windows kernel flaws
    Microsoft to address flaws in Windows, Office for Mac
    Microsoft fixes security update that breaks Internet Explorer
    What is the best database patch management process?
    Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
    Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
    Microsoft releases temporary fix for SMB2 zero-day vulnerability
    Microsoft issues SMB vulnerability advisory, patch pending

    IPsec VPN Security
    Best Remote Access Products
    How to set up a split-tunnel VPN in Windows Vista
    What is the difference between a VPN and remote control?
    A short enterprise VPN deployment guide
    From the ground up: Creating secure WLANs
    Can S/MIME, XML and IPsec operate in one protocol layer?
    How to create a secure network through a shared Internet connection
    What firewall controls should be placed on the VPN?
    VoIP tools, attacks could increase threat
    Best practices for processing financial data through remote servers
    IPsec VPN Security Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    BotHunter  (SearchSecurity.com)
    principle of least privilege (POLP)  (SearchSecurity.com)
    security identifier  (SearchSecurity.com)
    trusted computing  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts