Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Protocols and Routing
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Protocols and Routing IP, IPX and other protocol support

Reply
 
LinkBack Thread Tools
Old 03-06-2009, 01:11 AM   #1 (permalink)
Registered User
 
Join Date: Mar 2009
Posts: 1
OS: Windows Server 2008 Standard


netsh ipsec dynamic delete rule question

Hi all,

I'm trying to delete a dynamic ipsec rule, but it appears that Windows ipsec has a bug.

The following works fine. I create a mmpolicy, qmpolicy and a rule. I can then delete the rule with no issues:
netsh ipsec dynamic add mmpolicy name=test1 mmsecmethods="3DES-SHA1-2 3DES-MD5-2 3DES-SHA1-3"
netsh ipsec dynamic add qmpolicy name=test2 pfsgroup=grp1 qmsecmethods="ESP[3DES,MD5]:50000K/3600S"
netsh ipsec dynamic add rule srcaddr=192.168.69.200 dstaddr=192.168.11.1 mmpolicy=test1 qmpolicy=test2 protocol=ANY mirror=no conntype=all dstmask=255.255.255.255 psk=0000000000000000
netsh ipsec dynamic delete rule srcaddr=192.168.69.200 dstaddr=192.168.11.1 protocol=ANY srcport=0 dstport=0 mirrored=no conntype=all


The following works fine but throws an error. The rule is deleted, but the command reports "ERR IPsec[06011] : Specified MainMode Filter does not exist.
netsh ipsec dynamic add mmpolicy name=test1 mmsecmethods="3DES-SHA1-2 3DES-MD5-2 3DES-SHA1-3"
netsh ipsec dynamic add qmpolicy name=test2 pfsgroup=grp1 qmsecmethods="ESP[3DES,MD5]:50000K/3600S"
netsh ipsec dynamic add rule srcaddr=192.168.69.200 dstaddr=192.168.11.1 mmpolicy=test1 qmpolicy=test2 protocol=ANY mirror=no conntype=all dstmask=255.255.255.255 psk=0000000000000000 tunneldstaddr=127.0.0.1
netsh ipsec dynamic delete rule srcaddr=192.168.69.200 dstaddr=192.168.11.1 protocol=ANY srcport=0 dstport=0 mirrored=no conntype=all tunneldstaddr=127.0.0.1


We can check that the rule is gone by using the following command:
netsh ipsec dynamic show rule

The next example fails altogether to delete. Instead of specifying one address, a range is specifed. This is where I'm having problems.
netsh ipsec dynamic add mmpolicy name=test1 mmsecmethods="3DES-SHA1-2 3DES-MD5-2 3DES-SHA1-3"
netsh ipsec dynamic add qmpolicy name=test2 pfsgroup=grp1 qmsecmethods="ESP[3DES,MD5]:50000K/3600S"
netsh ipsec dynamic add rule srcaddr=192.168.69.200 dstaddr=192.168.11.0 mmpolicy=test1 qmpolicy=test2 protocol=ANY mirror=no conntype=all dstmask=255.255.255.0 psk=0000000000000000 tunneldstaddr=127.0.0.1
netsh ipsec dynamic delete rule srcaddr=192.168.69.200 dstaddr=192.168.11.0 protocol=ANY srcport=0 dstport=0 mirrored=no conntype=all tunneldstaddr=127.0.0.1


I know it's possible to delete all policys and rules using the following, but I just want to delete one rule, not all of them.
netsh ipsec dynamic delete all

Thanks to anyone who can help. Might be a bug. I'm using Windows Server 2008 Standard, but Vista should show the same behaviour.
hotdogger is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 01:36 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85