<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ian Hameroff : IPsec</title><link>http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx</link><description>Tags: IPsec</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Article Alert: Policy-Driven Network Access with Windows Server 2008</title><link>http://blogs.technet.com/ianhamer/archive/2008/03/15/article-alert-policy-driven-network-access-with-windows-server-2008.aspx</link><pubDate>Sun, 16 Mar 2008 04:41:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3004521</guid><dc:creator>ianhamer</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/3004521.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=3004521</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=3004521</wfw:comment><description>&lt;p&gt;While it has been nearly &lt;a href="http://blogs.technet.com/ianhamer/archive/2008/01/04/happy-new-job-er-year.aspx"&gt;three months since I moved from the role as product manager for Windows Server networking to the Exchange Server team&lt;/a&gt;, I still get the occasional opportunity to strut my old networking stuff.&amp;nbsp; &lt;/p&gt; &lt;p&gt;One such example is a recent article I co-authored with Amith Krishnan (product manager for &lt;a href="http://www.microsoft.com/nap"&gt;Network Access Protection&lt;/a&gt;) on creating a &lt;a href="http://blogs.technet.com/ianhamer/archive/2007/04/13/dodging-silver-bullet-syndrome-or-how-i-learned-to-stop-worrying-and-prepared-for-nap-part-1.aspx"&gt;policy-driven network access solution&lt;/a&gt; using a bunch of the new features of &lt;a href="http://www.microsoft.com/windowsserver2008"&gt;Windows Server 2008&lt;/a&gt;.&amp;nbsp; The article -- entitled &lt;a href="http://technet.microsoft.com/en-us/magazine/cc194389.aspx"&gt;Policy-Driven Network Access with Windows Server 2008&lt;/a&gt; -- appears in the &lt;a href="http://technet.microsoft.com/en-us/magazine/cc268370.aspx"&gt;March edition&lt;/a&gt; of Microsoft's &lt;a href="http://technet.microsoft.com/en-us/magazine/default.aspx"&gt;TechNet Magazine&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Here's the article synopsis:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;How do you allow network access to those who need it without sacrificing security? See how new technologies in Windows Server 2008, such as Windows Firewall with Advanced Security and Network Access Protection, let you implement a policy-based approach to help you achieve this goal.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Unfortunately, the online version of article doesn't offer you the opportunity to make comments on the article.&amp;nbsp; So, please feel free to post your thoughts or feedback to this blog posting.&lt;/p&gt; &lt;p&gt;Okay, back to Exchange for me.&amp;nbsp; I'm currently completely week 2 of 3 on the road doing focus groups around our future plans for Exchange Server.&amp;nbsp; Good stuff; albeit exhausting to be traveling across the US, Asia (currently in Tokyo) and then Europe. Yahoo!&lt;/p&gt; &lt;p&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3004521" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Firewall/default.aspx">Windows Firewall</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Secure+Wireless/default.aspx">Secure Wireless</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Test Drive Server and Domain Isolation!</title><link>http://blogs.technet.com/ianhamer/archive/2007/12/03/test-drive-server-and-domain-isolation.aspx</link><pubDate>Mon, 03 Dec 2007 22:26:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2605406</guid><dc:creator>ianhamer</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/2605406.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=2605406</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=2605406</wfw:comment><description>&lt;p&gt;Yes. &lt;/p&gt; &lt;p&gt;I agree that it took us long enough to get this thing posted since I first &lt;a href="http://blogs.technet.com/ianhamer/archive/2007/02/05/rsa-2007-day-2-opening-day.aspx"&gt;mentioned it back in February&lt;/a&gt;.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Nevertheless, you can &lt;u&gt;now&lt;/u&gt; download the kick ass &lt;a href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation&lt;/a&gt; demo/lab that Microsoft MVP and Virtualization and Security Guru &lt;a href="https://mvp.support.microsoft.com/profile=FBF14969-9244-4CD2-AFDD-BBBE443D1CC9"&gt;Ronald Beekelaar&lt;/a&gt; built for us:&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=13a0ab69-2113-482e-a6d1-911aff9e9e2d&amp;amp;displaylang=en"&gt;&lt;font size="3"&gt;Server and Domain Isolation Demo&lt;/font&gt;&lt;/a&gt;&lt;/p&gt; &lt;p align="left"&gt;This kit includes everything you need to test drive a Server and Domain Isolation deployment on Windows Server 2003 and Windows XP.&amp;nbsp; &lt;/p&gt; &lt;p align="left"&gt;Wait!&lt;/p&gt; &lt;p align="left"&gt;Did I say WS03 and XP?&lt;/p&gt; &lt;p align="left"&gt;Yes.&amp;nbsp; But, don't fret.&amp;nbsp; &lt;/p&gt; &lt;p align="left"&gt;We're working with Ron to get an updated version of the demo that highlights all the great stuff we've done in &lt;a href="http://www.microsoft.com/windowsvista"&gt;Windows Vista&lt;/a&gt; and &lt;a href="http://www.microsoft.com/windowsserver2008"&gt;Windows Server 2008&lt;/a&gt;.&amp;nbsp; This version (no pressure Ron!) should hit the streets around the RTM/Launch of WS08.&amp;nbsp; Stay tuned!&lt;/p&gt; &lt;p align="left"&gt;Okay, back to describing the one you now have at your disposal: You'll find 5 pre-configured VHDs and some &lt;a href="http://download.microsoft.com/download/a/4/3/a43592c2-973f-4896-9c62-c73611ed5932/SDI Demo - Script Steps (v2.1d).doc"&gt;great documentation&lt;/a&gt; that will step you through both basic and advanced S&amp;amp;DI scenarios.&amp;nbsp; Ron's done a great job with visualizations that help tell the story and explain the data flows, etc. when trying out the different scenarios (like the "Start Page" shown below).&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TestDriveServerandDomainIsolation_A0EB/sdi.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="372" alt="sdi" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TestDriveServerandDomainIsolation_A0EB/sdi_thumb.png" width="454" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p align="left"&gt;All you'll need to do to run the demo is &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=04D26402-3199-48A3-AFA2-2DC0B40A73B6&amp;amp;displaylang=en"&gt;download Virtual PC 2007&lt;/a&gt; (or use an existing &lt;a href="http://www.microsoft.com/windowsserversystem/virtualserver/"&gt;Virtual Server&lt;/a&gt; or Virtual PC installation) which you can get for free from &lt;a href="http://www.microsoft.com/virtualpc"&gt;http://www.microsoft.com/virtualpc&lt;/a&gt;.&lt;/p&gt; &lt;p align="left"&gt;After you've been wowed by the great stuff you can do with S&amp;amp;DI (which is an out of the box security solution with WS03, XP and Win2K, and WS08 and WinVista), visit our TechNet Server and Domain Isolation site at &lt;a href="http://www.microsoft.com/sdisolation"&gt;http://www.microsoft.com/sdisolation&lt;/a&gt; to learn more, review customer case studies, and download deployment guidance.&lt;/p&gt; &lt;p align="left"&gt;Have fun!&lt;/p&gt; &lt;p align="left"&gt;-- hama&lt;/p&gt; &lt;p align="left"&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2605406" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2003/default.aspx">Windows Server 2003</category></item><item><title>Broadcom Takes IPsec to Task (Offload That Is)!</title><link>http://blogs.technet.com/ianhamer/archive/2007/11/07/broadcom-takes-ipsec-to-task-offload-that-is.aspx</link><pubDate>Thu, 08 Nov 2007 05:49:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2362905</guid><dc:creator>ianhamer</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/2362905.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=2362905</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=2362905</wfw:comment><description>&lt;p&gt;Our friends over at &amp;nbsp;&lt;a href="http://www.broadcom.com"&gt;Broadcom&lt;/a&gt; announced on Tuesday (November 6th) a new super cool, &lt;a href="http://www.broadcom.com/press/release.php?id=1073185"&gt;65nm Gigabit Ethernet controller&lt;/a&gt; that will incorporate support for Window Vista's &lt;a href="http://www.microsoft.com/whdc/device/network/IPSec_offload.mspx"&gt;IPsec Task Offload&lt;/a&gt; functionality!&lt;/p&gt; &lt;p&gt;As my boss' boss said in the press release:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;"Thanks to Broadcom's inclusion of IPsec task offload support, our mutual customers will have even greater flexibility when implementing the IPsec features of Windows Vista and Windows Server® 2008," said Mike Schutz, Director of Security and Access Product Management at Microsoft. "By easing any potential performance tradeoffs, these latest NetXtreme security features will help further the adoption of such advanced Microsoft Windows security solutions as &lt;a href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation&lt;/a&gt; and &lt;a href="http://www.microsoft.com/nap"&gt;Network Access Protection&lt;/a&gt;."&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Effectively, with IPsec task offload support, many of the CPU intensive work required for hashing packets or encryption (if you're using the encryption options) can be moved to the NIC.&amp;nbsp; This frees up the many CPU(s) for more interesting tasks, like running applications or surfing the web for stuff.&lt;/p&gt; &lt;p&gt;This means there'll be one less reason to not consider using IPsec as the great network security tool I've written about for sometime now!&lt;/p&gt; &lt;p&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2362905" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Scalable+Networking/default.aspx">Scalable Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Greetings from the Future (Or, At Least GMT+8)</title><link>http://blogs.technet.com/ianhamer/archive/2007/09/14/greetings-from-the-future-or-at-least-gmt-8.aspx</link><pubDate>Sat, 15 Sep 2007 06:41:31 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1960871</guid><dc:creator>ianhamer</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/1960871.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=1960871</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=1960871</wfw:comment><description>&lt;p&gt;It's the Saturday following my week here in &lt;a href="http://en.wikipedia.org/wiki/Kuala_lumpur"&gt;Kuala Lumpur&lt;/a&gt; (aka KL) and &lt;a href="http://www.microsoft.com/malaysia/techedsea2007"&gt;TechEd 2007 SEA&lt;/a&gt; (aka South East Asia).&amp;nbsp; The week was a good time, and it was great to connect with the local 'softies, MVPs, partners, and of course, the regional customers.&lt;/p&gt; &lt;p&gt;I delivered two sessions, both basically repeats of my sessions at TechEd 2007 USA:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Implementing the IPsec Simple Policy Update for Windows XP and Windows Server 2003  &lt;li&gt;Enabling Policy-Driven Network&amp;nbsp;Access&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The second of the two was based on&amp;nbsp;my TLC&amp;nbsp;interactive theater session by the same name.&amp;nbsp; However,&amp;nbsp;I&amp;nbsp;re-worked the&amp;nbsp;slides and introduce a pretty neat demo.&amp;nbsp; &lt;/p&gt; &lt;p&gt;The demo illustrates a few of the Policy-Driven Network Access features of Windows Server 2008 and Windows Vista.&amp;nbsp; In particular, &lt;a href="http://www.microsoft.com/nap"&gt;Network Access Protection&lt;/a&gt; (using &lt;a href="http://www.microsoft.com/ipsec"&gt;IPsec&lt;/a&gt; enforcement), and &amp;nbsp;the &lt;a href="http://www.microsoft.com/technet/community/columns/cableguy/cg0106.mspx"&gt;Windows Firewall with Advanced Security&lt;/a&gt;. &lt;/p&gt; &lt;p&gt;Here's a snap-shot of my demo environment: &lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/GreetingsfromtheFutureOrAtLeastGMT8_A444/TechEd_SEA_Demo.jpg" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="389" alt="Policy-Driven Network Access Demo from TechEd 2007 SEA" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/GreetingsfromtheFutureOrAtLeastGMT8_A444/TechEd_SEA_Demo_thumb.jpg" width="525" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;The actual physical setup included two laptops and simple switch.&amp;nbsp; My trusty ThinkPad T60p booted the client side (Windows Vista Enterprise) off of my second hard disk in the UltraBay, and my Acer Ferrari ran the three Windows Server 2008 servers as VMs via Virtual Server 2005 R2 SP1.&amp;nbsp; I'm looking forward to trying these out on Windows Server virtualization!&lt;/p&gt; &lt;p&gt;I had also planned on showing our &lt;a href="http://www.microsoft.com/wifi"&gt;Secure Wireless LAN&lt;/a&gt; solution (aka using the built in 802.1X supplicant in Windows Vista, the WS08 Network Policy Server/RADIUS, and EAP-TLS), but the &lt;a href="http://www.linksys.com/servlet/Satellite?c=L_Product_C2&amp;amp;childpagename=US%2FLayout&amp;amp;cid=1147187335899&amp;amp;pagename=Linksys%2FCommon%2FVisitorWrapper&amp;amp;lid=3589987090B01"&gt;Linksys wireless access point&lt;/a&gt; I brought along was only rated for 120V/60Hz.&amp;nbsp; This certainly a disappointment.&amp;nbsp; I mean, no offense to our friends at Cisco, but come on!&amp;nbsp; Almost every piece of technology I own can handle, at the very least 100-240V.&amp;nbsp; Well, thanks to a local colleague, I was able to re-work the demo with a borrowed switch.&lt;/p&gt; &lt;p&gt;The demo was a bit of a re-work of the &lt;a href="http://blogs.technet.com/ianhamer/archive/2007/05/23/the-2007-tour-from-secman-to-winhec-to-interop-and-on-to-teched.aspx"&gt;Security and Policy Enforcement demo I showed at WinHEC&lt;/a&gt;.&amp;nbsp; I cut the bits about how AD Rights Management Services integrates with MOSS, blah blah, and focused more on the network controls.&amp;nbsp; Like being able to perform network layer authentications using health (aka NAP Health Certifications) and User credentials (via the Windows Firewall with Advanced Security's "Allow if Secure" filters in conjunction with Connection Security Rules).&amp;nbsp; I plan on expanding the demo even further to include a few more bells and whistles (and a little more time spent on the back-end policy creation).&amp;nbsp; &lt;/p&gt; &lt;p&gt;I'll be speaking to an SBS User Group in Singapore on Tuesday, and I hope to re-run the demo there with these additional bells and whistles.&lt;/p&gt; &lt;p align="left"&gt;To close: We had our company meeting on September 6th.&amp;nbsp; This happened to coincide with flight from Seattle to Singapore.&amp;nbsp; Nevertheless, I attempted to get into the spirit of the Company Meeting, by wearing the bright orange (wow!) long sleeved T-shirt our&amp;nbsp;entire team had planned on showing off at the big show, but for me on the airplane:&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/GreetingsfromtheFutureOrAtLeastGMT8_A444/FF_Shirt_on_Plane.jpg" atomicselection="true"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="400" alt="FF_Shirt_on_Plane" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/GreetingsfromtheFutureOrAtLeastGMT8_A444/FF_Shirt_on_Plane_thumb.jpg" width="500" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;You can almost see the flag from the Windows Server 2008 logo on my left arm.&amp;nbsp; I attempted to capture the whole of the sleeve by flexing it a bit while using my Palm Treo 750's built-in camera to snap the shot.&amp;nbsp; At the same time, I was trying to avoid making it looking I was trying to show off my "guns" (even though I have been working out at the Pro Club and it would be nice if you did notice!).&amp;nbsp; Talk about team pride!&lt;/p&gt; &lt;p&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1960871" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Firewall/default.aspx">Windows Firewall</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Brand Spanking New Server and Domain Isolation Case Study</title><link>http://blogs.technet.com/ianhamer/archive/2007/06/18/brand-spanking-new-server-and-domain-isolation-case-study.aspx</link><pubDate>Tue, 19 Jun 2007 00:03:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1285891</guid><dc:creator>ianhamer</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/1285891.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=1285891</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=1285891</wfw:comment><description>&lt;p&gt;Hot off the presses, we've just&amp;nbsp;published a brand spanking new &lt;a href="http://www.microsoft.com/casestudies/"&gt;customer case study&lt;/a&gt; about how the &lt;a href="http://www.city.sapporo.jp/city/english/"&gt;City of Sapporo&lt;/a&gt; (Japan) implemented a &lt;a href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation&lt;/a&gt; solution.&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;Here's a link to the case study (which you can also find with several case studies on our our &lt;a href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation TechNet&lt;/a&gt; site):&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000000161"&gt;&lt;strong&gt;Major Japanese Municipal Principal Government Achieves Security Compliance at Nil Cost&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Here's a little bit about what you'll learn:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;In 2004, the local government of the City of Sapporo, Japan, established a security policy to define and control how the city maintained its information assets. With 12,000 users working in almost 870 departments and limited enforcement resources available in the form of staff and operational procedures, policy compliance proved difficult to achieve. By implementing a Server and Domain Isolation solution based on Microsoft Windows Internet Protocol Security (IPsec) and Active Directory, the City of Sapporo was able to implement cost-effective end-point authentication to dynamically segment its Windows environment into more secure and isolated logical networks, without requiring costly changes to its network infrastructure or applications. The solution has improved information security and reduced the risk of unauthorized access to confidential data on the organization’s Intranet.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;What's neat?&amp;nbsp; &lt;/p&gt; &lt;p&gt;They did all this on Windows Server 2003, Windows XP and Windows 2000.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Does that mean there's nothing in Windows Vista or Windows Server 2008 that you should be interested?&amp;nbsp; &lt;/p&gt; &lt;p&gt;Not true.&lt;/p&gt; &lt;p&gt;With Windows Vista and Windows Server 2008, we make deploying a solution like the one outlined in the above case study easier to configure, deploy and maintain.&amp;nbsp; Neat stuff!&lt;/p&gt; &lt;p&gt;And, they've&amp;nbsp;also laid a foundation that can be used to help enforce network access once Windows &lt;a href="http://www.microsoft.com/getabeta3"&gt;Server 2008&lt;/a&gt; ships and introduces &lt;a href="http://www.microsoft.com/nap"&gt;Network Access Protection.&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Enjoy!&lt;/p&gt; &lt;p&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1285891" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2003/default.aspx">Windows Server 2003</category></item><item><title>Tech·Ed 2007 - Day 5: IPsecapalooza 2007 (recap)</title><link>http://blogs.technet.com/ianhamer/archive/2007/06/08/tech-ed-2007-day-5-ipsecapalooza-2007-recap.aspx</link><pubDate>Fri, 08 Jun 2007 22:53:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1185955</guid><dc:creator>ianhamer</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/1185955.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=1185955</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=1185955</wfw:comment><description>&lt;p&gt;Day 5 (which was yesterday) was rough one.&amp;nbsp; I'd been fighting a cold for most of my visit here in FLA, and it came back to haunt me during my&amp;nbsp;last&amp;nbsp;session Thursday afternoon.&lt;/p&gt; &lt;p&gt;I did a spiel about how you can simplify your Windows XP and Windows Server 2003 based &lt;a href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation&lt;/a&gt; deployments with the nearly a year old &lt;a href="http://www.microsoft.com/technet/network/ipsec/simplepolicy.mspx"&gt;Simple Policy Update&lt;/a&gt;.&amp;nbsp; Although it started off well, my energy level did slump a little bit towards then end,&amp;nbsp;which likely explains this comment from one participation:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;&lt;font face="Verdana" color="#000080" size="2"&gt;"speaker was to [sic]&amp;nbsp;mono toned and was hard to keep focused."&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Yup, I was a bit out of it, but I do appreciate all the feedback and the decent evaluation scores.&amp;nbsp; Next time, I'll be sure to chug my Emergenc-C before coming down to TechEd 2008 (or whatever conference).&lt;/p&gt; &lt;p&gt;Nonetheless, we discussed why you should even think about &lt;a href="http://www.microsoft.com/ipsec"&gt;IPsec&lt;/a&gt; to help address all that craziness today's world of networking has brought on. I did a quick demo of Server and Domain Isolation, and closed with a bunch of stuff on the Simple Policy Update.&lt;/p&gt; &lt;p&gt;After the session, I did about&amp;nbsp;a 30 minute stretch at the booth and went back to the hotel to rest.&lt;/p&gt; &lt;p&gt;Before I left, I was notified by one of my "booth babes" (it might have been Sean (again)) that my Server and Domain Isolation collateral had the wrong URL (i.e. a typo) on the front side:&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day5IPsecapalooza2007recap_DF77/TechEd04.png" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="382" alt="TechEd04" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day5IPsecapalooza2007recap_DF77/TechEd04_thumb.png" width="525" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;Ugh.&lt;/p&gt; &lt;p&gt;Good news, the link on the backside (&lt;a href="http://www.microsoft.com/sdisolation"&gt;http://www.microsoft.com/sdisolation&lt;/a&gt;) does work.&amp;nbsp; Or you can just click on this one.&lt;/p&gt; &lt;p&gt;Changing subjects for one moment: I'm at the Yellow TLC (a near-ghost town) with less than 10 minutes left before the show floor closes.&amp;nbsp; We're almost done with TechEd 2007!&lt;/p&gt; &lt;p&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1185955" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Tech·Ed 2007 - Day 4.5: Tolly Group White Paper Published!</title><link>http://blogs.technet.com/ianhamer/archive/2007/06/07/tech-ed-2007-day-4-5-tolly-group-white-paper-published.aspx</link><pubDate>Thu, 07 Jun 2007 19:56:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1174147</guid><dc:creator>ianhamer</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/1174147.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=1174147</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=1174147</wfw:comment><description>&lt;p&gt;So, I've talked a lot about this white paper that the &lt;a href="http://www.tollygroup.com/"&gt;Tolly Group&lt;/a&gt; published in my Networking Session on Tuesday.&amp;nbsp; Well,&amp;nbsp;it is now up and ready for download from our &lt;a href="http://www.microsoft.com/networking"&gt;TechNet Networking site&lt;/a&gt;!&lt;/p&gt; &lt;p&gt;Here's the direct link:&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://download.microsoft.com/download/4/b/4/4b455e48-72c4-4a04-b9a5-892fd497087a/TollyResults.pdf"&gt;Enhanced Network Performance with Microsoft Windows Vista and Windows Server 2008&lt;/a&gt;&lt;/p&gt; &lt;p align="left"&gt;Here's a little excerpt to tantalize your interest:&amp;nbsp;&lt;/p&gt; &lt;blockquote&gt; &lt;p align="left"&gt;&lt;em&gt;&lt;font face="Verdana" color="#000080"&gt;&lt;strong&gt;"Just upgrading client PCs to Microsoft's Windows Vista can yield throughput and time-to-completion improvements of up to 2.5X over Windows XP. Complete migration of servers to Windows Server 2008 can yield throughput and time-to-completion improvements of up to 3.5X over Windows XP/Windows Server 2003."&lt;/strong&gt;&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p align="left"&gt;Don't forget to check out the recent article that John Fontana published that talks about this report:&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://www.networkworld.com/news/2007/060607-vista-study.html?page=1"&gt;Microsoft-sponsored study says Vista improves TCP/IP performance&lt;/a&gt;&lt;/p&gt; &lt;p align="left"&gt;Okay, time to prep for my afternoon session on the &lt;a href="http://www.microsoft.com/technet/network/ipsec/simplepolicy.mspx"&gt;IPsec Simple Policy Update for Windows XP and Windows Server 2003&lt;/a&gt;.&lt;/p&gt; &lt;p align="left"&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1174147" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Tech·Ed 2007 - Day 4: TLC Fun! (Recap)</title><link>http://blogs.technet.com/ianhamer/archive/2007/06/07/tech-ed-2007-day-4-tlc-fun-recap.aspx</link><pubDate>Thu, 07 Jun 2007 17:42:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1172954</guid><dc:creator>ianhamer</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/1172954.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=1172954</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=1172954</wfw:comment><description>&lt;p&gt;Once more, I'm plagued by horrifically poor&amp;nbsp;bandwidth on the hotel network.&amp;nbsp; &lt;/p&gt; &lt;p&gt;After having dinner with Sean (aka Sean&lt;a href="http://www.microsoft.com/ipv6"&gt;v6&lt;/a&gt;)&amp;nbsp;at the &lt;a href="http://www.bahamabreeze.com/"&gt;Bahama Breeze&lt;/a&gt;, and dodging some hardcore downpours with lots of loud thunder and nearby lightening to boot, I returned to my humble temporary abode to check email, surf for interesting tidbits to kick-off my Thursday afternoon IPsec session with, and -- YIKES! -- discover 89 kbps download rates.&lt;/p&gt; &lt;p&gt;I normally travel with one of them &lt;a href="http://www.linksys.com/servlet/Satellite?c=L_Product_C2&amp;amp;childpagename=US%2FLayout&amp;amp;cid=1122062241008&amp;amp;pagename=Linksys%2FCommon%2FVisitorWrapper"&gt;Linksys Wireless-G Travel Routers&lt;/a&gt;, which provides a bit of wireless freedom even if the hotel doesn't offer such.&amp;nbsp; Turns out that the hotel has both wired (including a&amp;nbsp;"bank pen like attached CAT-5 cable -- see picture below) and wireless.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day4TLCFunRecap_95B4/TechEd03_1.png" atomicselection="true"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="400" alt="TechEd03" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day4TLCFunRecap_95B4/TechEd03_thumb_1.png" width="500" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;I went through every possible&amp;nbsp;iteration of connectivity options, and actually discovered that my private WLAN yielded better transfer rates than being plugged in directly on the hotel's copper, or using their WLAN.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Amazing!&lt;/p&gt; &lt;p&gt;Sean shared similar frustration, and we both wondered why a conference town like Orlando doesn't have more than "&lt;a href="http://en.wikipedia.org/wiki/Tin_can_telephone"&gt;two-cans with string&lt;/a&gt;" type network access to the "Internets".&amp;nbsp; &lt;/p&gt; &lt;p&gt;This morning was a little bit better:&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day4TLCFunRecap_95B4/Download_Speed.png" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="232" alt="Download_Speed" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day4TLCFunRecap_95B4/Download_Speed_thumb.png" width="600" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;Anyhow.&lt;/p&gt; &lt;p&gt;Yesterday afternoon I delivered my "Enabling Policy-Driven Network Access" TLC Interactive Theater session (formerly known as Chalk Talks), to a great audience.&amp;nbsp; The session was (more or less) a mini-breakout, and it appeared to be well received.&amp;nbsp; We talked about a long list of built-in Windows Server 2008 and Windows Vista network security functionality that can help you embrace more policy-driven network access.&amp;nbsp; &lt;/p&gt; &lt;p&gt;The topics included:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://www.microsoft.com/technet/network/wf/default.mspx"&gt;Windows Firewall with Advanced Security&lt;/a&gt; (aka the new Windows Firewall)  &lt;li&gt;&lt;a href="http://www.microsoft.com/ipsec"&gt;IPsec&lt;/a&gt; enhancements  &lt;li&gt;&lt;a href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation&lt;/a&gt;  &lt;li&gt;&lt;a href="http://www.microsoft.com/wifi"&gt;Secure Wireless LAN&lt;/a&gt;  &lt;li&gt;&lt;a href="http://www.microsoft.com/nap"&gt;Network Access Protection&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;If you attended the session, but would like a copy of the presentation deck (which is not up on &lt;a href="http://www.msteched.com/"&gt;CommNet&lt;/a&gt;) &lt;a href="http://blogs.technet.com/ianhamer/contact.aspx"&gt;please contact me&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;We also had a little fun yesterday with the &lt;a href="http://www.microsoft.com/security/teched/default.mspx"&gt;Virtual TechEd Security Track&lt;/a&gt; folks.&amp;nbsp; &lt;a href="http://brianseitz.spaces.live.com/"&gt;Brian Seitz&lt;/a&gt; shot a video of (approx. 10 minutes) me and &lt;a href="https://mvp.support.microsoft.com/profile=240C8A9D-901D-4353-B5C3-3811E1AEB9CE"&gt;Rodrigo&lt;/a&gt; (our MVP) talking about Server and Domain Isolation on the show floor, and &lt;a href="http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=49593"&gt;Rodrigo's experience deploying the solution at his university in Brazil&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Check it out:&lt;/p&gt; &lt;p&gt; &lt;center&gt;&lt;embed name="msn_soapbox" pluginspage="http://macromedia.com/go/getflashplayer" src="http://images.soapbox.msn.com/flash/soapbox1_1.swf" width="432" height="364" type="application/x-shockwave-flash" quality="high" wmode="transparent" flashvars="c=v&amp;amp;v=5e2e5a37-838f-4ca8-8264-ed128949757a"&gt;&lt;/embed&gt;&lt;br&gt;&lt;a title="Ian Hameroff at TechEd" href="http://soapbox.msn.com/video.aspx?vid=5e2e5a37-838f-4ca8-8264-ed128949757a" target="_new"&gt;Video: Ian Hameroff at TechEd&lt;/a&gt;&lt;/center&gt; &lt;p&gt;&lt;/p&gt; &lt;p&gt;You can see more cool stuff like this up on Brian's blog at: &lt;a href="http://brianseitz.spaces.live.com"&gt;http://brianseitz.spaces.live.com&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;For fans of my session from the Tuesday (SRV310 - Deploying High Performance and Scalable Networking with Windows Server 2008), here's an article that talks about the Tolly Group performance report that will be posted to MSCOM very shortly (I promise!) that John Fontana from Network World posted yesterday afternoon:&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://www.networkworld.com/news/2007/060607-vista-study.html?page=1"&gt;Microsoft-sponsored study says Vista improves TCP/IP performance&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Okay, time to get sorted and over to The O.C.C.C.!&amp;nbsp; I have one more session this afternoon SEC309 - Implementing the IPsec Simple Policy Update for Microsoft Windows Server 2003 and Windows XP.&amp;nbsp; Here's the abstract:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font face="Verdana" color="#000080"&gt;&lt;em&gt;Common IPsec-based scenarios, like Server and Domain Isolation, require the configuration of an IPsec policy that contains rules for protected and permitted traffic. For some enterprise deployments, the IPsec policy rules can require hundreds of IP filter definitions that must be maintained over time. The Simple Policy Update for Microsoft Windows XP and Windows Server 2003 changes the behavior of IPsec negotiation so that the IPsec policy rules can be simplified, in some cases drastically reducing the number of required IP filters and their ongoing maintenance. This session dives into what these changes are and how they can be applied to both existing and new deployments of Server and Domain Isolation.&lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Don't forget to stop by the show floor (aka the Yellow TLC) and say hello!&lt;/p&gt; &lt;p&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1172954" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Firewall/default.aspx">Windows Firewall</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Secure+Wireless/default.aspx">Secure Wireless</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2003/default.aspx">Windows Server 2003</category></item><item><title>Tech·Ed 2007 - Day 2: Opening Day</title><link>http://blogs.technet.com/ianhamer/archive/2007/06/04/tech-ed-2007-day-2-opening-day.aspx</link><pubDate>Mon, 04 Jun 2007 19:23:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1152579</guid><dc:creator>ianhamer</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/1152579.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=1152579</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=1152579</wfw:comment><description>&lt;P&gt;So.&amp;nbsp; I started my day out battling a non-late night out based headache ("yeah, right Hameroff" -- no, seriously, I hit the hay around 10:30p) and then&amp;nbsp;confused by the TechEd 2007 shuttle buses.&amp;nbsp; I'll explain the latter more.&lt;/P&gt;
&lt;P&gt;At 9:30a-ish, I stood in front of my hotel for the #2 shuttle bus to arrive.&amp;nbsp; My new friend -- who I call "the dude sitting in the beach chair outside the front door of the hotel on his cell phone and half reading a novel of some sorts" -- let me know that the next bus was moments away.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;First, the #9 when by and about 5 minutes later my bus arrived.&amp;nbsp; We made one more stop at the hotel adjacent to mine, and then (I assumed) we were off to the convention center.&amp;nbsp; Well, we continued past the South O.C.C.C. (where TechEd is based), confusing most on the bus.&amp;nbsp; I thought that we were going to take a different entrance than we did on Sunday, but that theory was shot dead as we&amp;nbsp;sat in the left hand turning lane, waiting for the light to change so we could turn into the West building of &amp;nbsp;the O.C.C.C.&amp;nbsp; Just as I was about to leap up and say, "hey, wrong building dude!" we pulled up to a sign outside of the West building that read "TechEd 2007 Keynote -- Hall D."&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Even with this obvious clue, just about everyone got off the bus.&amp;nbsp; Two of us asked the driver if he was going to South building next, and we stayed on for the rest of the right.&lt;/P&gt;
&lt;P&gt;Exciting, eh?&lt;/P&gt;
&lt;P&gt;Today's edition of the show was a great way to&amp;nbsp;start off TechEd '07.&amp;nbsp; The booth had some decent traffic through the day (with the normal ups and downs in crowd sizes).&amp;nbsp; Our expert booth staff spoke with customers and partners about our network solutions, and even took time out to reach expo floor characters like Sean Siler did in the picture below:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day2OpeningDay_9151/TechEd02.png" atomicselection="true" mce_href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day2OpeningDay_9151/TechEd02.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=400 alt=TechEd02 src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day2OpeningDay_9151/TechEd02_thumb.png" width=500 border=0 mce_src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/TechEd2007Day2OpeningDay_9151/TechEd02_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;We also had a visit from Ron Beekelaar (MVP and creator of our Server and Domain Isolation demo), and we chatted about the next generation of the demo kit to include Windows Vista and eventually Windows Server 2008.&lt;/P&gt;
&lt;P&gt;Rodrigo, our MVP booth staffer, was a bit surprised by the limited knowledge of the power of Server and Domain Isolation.&amp;nbsp; But, it's great that we have this new demo to increase awareness.&lt;/P&gt;
&lt;P&gt;Okay, time to head out the Contemporary Hotel on the Disney World campus for dinner with the crew.&amp;nbsp; More to come tomorrow!&lt;/P&gt;
&lt;P&gt;-- hama&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1152579" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Miscellaneous/default.aspx">Miscellaneous</category></item><item><title>Windows Server 2008 Network Security Webcast</title><link>http://blogs.technet.com/ianhamer/archive/2007/05/25/windows-server-2008-network-security-webcast.aspx</link><pubDate>Sat, 26 May 2007 01:07:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1059468</guid><dc:creator>ianhamer</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/1059468.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=1059468</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=1059468</wfw:comment><description>&lt;p&gt;The next few days in the US is &lt;a href="http://en.wikipedia.org/wiki/Memorial_day"&gt;Memorial Day&lt;/a&gt; weekend, also known as the unofficial start to summer.&amp;nbsp; The means there will be plenty of barbeques, parties, and a Monday off.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Well, if you find yourself without something to done during this extended weekend, why not checkout this 90 minute TechNet webcast Amith Krishnan (NAP product manager) and I recorded back on May 17th:&lt;/p&gt; &lt;p&gt;&lt;b&gt;&lt;a href="http://www.microsoft.com/events/EventDetails.aspx?CMTYSvcSource=MSCOMMedia&amp;amp;Params=%7eCMTYDataSvcParams%5e%7earg+Name%3d%22ID%22+Value%3d%221032336319%22%2f%5e%7earg+Name%3d%22ProviderID%22+Value%3d%22A6B43178-497C-4225-BA42-DF595171F04C%22%2f%5e%7earg+Name%3d%22lang%22+Value%3d%22en%22%2f%5e%7earg+Name%3d%22cr%22+Value%3d%22US%22%2f%5e%7esParams%5e%7e%2fsParams%5e%7e%2fCMTYDataSvcParams%5e"&gt;TechNet Webcast: Windows Server 2008: Advancing Network Security (Level 300)&lt;/a&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;Here's the abstract of what was covered:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;&lt;font face="Times New Roman" size="3"&gt;Among the long list of enhancements and innovations coming in Windows Server 2008&amp;nbsp;are a number of networking advancements and policy-driven network security features. In this webcast, we discuss the next generation of networking features in Windows Server 2008&amp;nbsp;and the network security solution scenarios these features enable. We examine the new Windows Firewall with Advanced Security, Server and Domain Isolation, and Network Access Protection (NAP). Discover how you can use these new networking innovations to provide your users with a more secure, reliable, and cost-effective connection experience.&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;We answered a bunch of questions on the call, but happy to answer any more you might have after watching the replay.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Enjoy, and have a great extended weekend!&lt;/p&gt; &lt;p&gt;-- hama&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1059468" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Firewall/default.aspx">Windows Firewall</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPv6/default.aspx">IPv6</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Secure+Wireless/default.aspx">Secure Wireless</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Using Server Isolation to Protect Your KMS Servers</title><link>http://blogs.technet.com/ianhamer/archive/2007/05/01/using-server-isolation-to-protect-your-kms-servers.aspx</link><pubDate>Tue, 01 May 2007 20:01:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:860512</guid><dc:creator>ianhamer</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/860512.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=860512</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=860512</wfw:comment><description>&lt;p&gt;Did you know that you can use a targeted &lt;a href="http://www.microsoft.com/ipsec"&gt;IPsec&lt;/a&gt;-based Isolation solution to help reduce the risk of unauthorized access to your &lt;a href="http://technet.microsoft.com/en-us/windowsvista/bb335280.aspx"&gt;Key Management Service (KMS)&lt;/a&gt; Servers?&lt;/p&gt; &lt;p&gt;Yup.&amp;nbsp; It's true.&amp;nbsp; This is a great example of using "&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=93bed81a-d073-4c2e-866f-e062dc2213b7&amp;amp;DisplayLang=en"&gt;Server Isolation&lt;/a&gt;" as a means to add granular network access controls and end-to-end host authentication to critical services and applications.&amp;nbsp; Think of it as a mini-virtual network that doesn't require any mucking around with your switches or router ACLs.&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/UsingServerIsolationtoProtectYourKMSServ_8CF4/kmsipsec1.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="304" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/UsingServerIsolationtoProtectYourKMSServ_8CF4/kmsipsec_thumb1.png" width="500" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Like &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=156c73a1-f9c2-41c7-b5c1-a509fb255447&amp;amp;DisplayLang=en"&gt;Domain Isolation&lt;/a&gt;, it leverages IPsec policies and credentials managed and distributed via Active Directory.&lt;/p&gt; &lt;p&gt;Well, let's cut to the chase...here a link to the IT Pro white paper that includes step-by-step guidance on using &lt;em&gt;"Server Isolation with IPsec and Active Directory to secure access to KMS hosts, and provides step-by-step guidance for deploying such a solution on Windows Vista, Windows Server “Longhorn” or Windows Server 2003."&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=c13c9d27-a3c9-4626-938b-fed6404d8c5e&amp;amp;displaylang=en"&gt;Using Server Isolation to Protect the Key Management Service (KMS)&lt;/a&gt;&lt;/p&gt; &lt;p&gt;If you've been curious about how IPsec-based solution scenarios -- like &lt;a href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation&lt;/a&gt;&amp;nbsp;-- can work in your organizations, but were concerned about the wider scale impact to your network, solution scenarios like the one outline in the aforementioned white paper are a&amp;nbsp;great place to start.&amp;nbsp; Service Isolation of your KMS servers offers you&amp;nbsp;a&amp;nbsp;way to get your "hands dirty" with IPsec, deliver immediate value, while not "biting off more than you're ready to chew."&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=860512" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category></item><item><title>Joint IPv6 White Paper Scales to 256-Bit Length Addresses</title><link>http://blogs.technet.com/ianhamer/archive/2007/04/30/joint-ipv6-white-paper-scales-to-256-bit-length-addresses.aspx</link><pubDate>Tue, 01 May 2007 07:46:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:855743</guid><dc:creator>ianhamer</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/855743.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=855743</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=855743</wfw:comment><description>&lt;p&gt;Okay, that was a little bit sensational, if not an outright fib.&amp;nbsp; &lt;/p&gt; &lt;p&gt;What's no joke is a newly published joint white paper &lt;a href="http://www.juniper.net"&gt;Juniper Networks&lt;/a&gt; and &lt;a href="http://www.microsoft.com/ipv6"&gt;Microsoft&lt;/a&gt; have co-developed to talk about deploying end-to-end IPv6 scenarios.&lt;/p&gt; &lt;p&gt;Heck, we felt that whole end-to-end bit was such a good thing we&amp;nbsp;named the white paper after it (which you can find here):&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=b3611543-58b5-4ccc-b6ce-677ebb2a520d&amp;amp;displaylang=en"&gt;Enabling the Next Generation of Networking with End-to-End IPv6&lt;/a&gt;&lt;/p&gt; &lt;p align="left"&gt;In addition to us lackeys from the product groups, we had folks from the US Federal/public sector&amp;nbsp;teams at both Juniper and Microsoft collaborate on this paper to ensure it spoke to the requirements that you folks in the federal agencies and related industries are facing as you seek to deploy IPv6.&lt;/p&gt; &lt;p align="left"&gt;Hey, how are those deployments going, by the way?&lt;/p&gt; &lt;p align="left"&gt;Here's a sampling of the white paper brought to you by way of the infamous executive summary:&lt;/p&gt; &lt;blockquote&gt; &lt;p align="left"&gt;&lt;em&gt;&lt;font face="Courier New" color="#0000ff"&gt;&lt;strong&gt;As connectivity converges and develops ubiquity many devices are added to the Internet. This trend has created projections of address shortages. Internet Protocol version 6 (IPv6) has promised a solution to this issue. In this paper, Microsoft and Juniper combine their leading networking knowledge to show customers how to adopt IPv6 technology. The paper first looks at the changing expectations of IPv6 with the growth of IPv6-enabled applications like Microsoft Windows Meeting Space in Windows Vista. Next the paper discusses the relationship of each component in an IPv6 implementation. The paper closes with some suggestions on functionality, equipment and deployment scenarios that highlight key aspects of a robust end-to-end IPv6 transition.&lt;/strong&gt;&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p align="left"&gt;As the summary mentions, the white paper covers off a bunch of flexible deployment strategies that leverage transitional technologies baked into Windows Vista and Windows Server "Longhorn" to full blown dual-stacking Juniper gear working in concert with the native IPv6 support in the aforementioned Windows releases (like the graphic below illustrates).&lt;/p&gt; &lt;p align="left"&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/JointIPv6WhitePaperScalesto256BitLengthA_100E8/junmsv6%5B2%5D.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="267" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/JointIPv6WhitePaperScalesto256BitLengthA_100E8/junmsv6_thumb%5B2%5D.png" width="500" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p align="left"&gt;STOP THE PRESSES! DID YOU ACTUALLY THINK YOU'D GET AWAY WITHOUT GETTING AN IPsec PITCH?&amp;nbsp; SUCKER!&lt;/p&gt; &lt;p align="left"&gt;I'll admit the above was a bit silly, if not juvenile, but this is the little fun I get to have blogging offline while drinking horrific coffee cruising at 35,000 ft en route to Los Angeles to support the &lt;a href="http://blogs.technet.com/ianhamer/archive/2007/04/19/that-s-right-you-re-in-control.aspx"&gt;big joint Forefront/System Center launch on Wednesday&lt;/a&gt;.&amp;nbsp;&lt;/p&gt; &lt;p align="left"&gt;Well, back to the IPsec pitch.&amp;nbsp; As you all know, my day job is minding the Internet protocols suite in Windows Server.&amp;nbsp; Since there are way too many to count on the knurled fingers of the&amp;nbsp;guy siting next to me (yeah, this dude was chewing and picking at his nails for a good 30 minutes until we took off and the engine noise lulled him to sleep), we primarily focus on a few key ones that enable our major networking scenarios (like Server and Domain Isolation and NAP which uses IPsec).&amp;nbsp; &lt;/p&gt; &lt;p align="left"&gt;I happen to think IPv6 migration is a pretty significant scenario that can also benefit from the cost-effective end-point authentication features of IPsec (as it was originally intended and realized with IPv6).&amp;nbsp; I also happen to know that IPsec can potentially introduce a full list of interoperability challenges that you may not wish to tackle.&amp;nbsp;&amp;nbsp; We're trying to work out how to strike the right balance between true end-to-end host authentication (not just at the network on ramps) while still preserving the network management and optimization features you've deployed are will consider deploying (say, WAN optimization).&amp;nbsp;&lt;/p&gt; &lt;p align="left"&gt;Well, it's important to look to the larger challenges (and risks) you are looking to address and we could certainly use your feedback to make sure we drive the right set of features into the platform and through our partner eco-system.&amp;nbsp; I'm not going to reiterate the &lt;a href="http://blogs.technet.com/ianhamer/archive/2006/01/24/418043.aspx"&gt;IPsec makes IPv6 better pitch&lt;/a&gt;, since I already blogged on this&amp;nbsp;many times.&amp;nbsp; Instead, I ask you to share your thoughts about how you think IPsec can help make your future IPv6 work more secure and scalable.&lt;/p&gt; &lt;p align="left"&gt;Well, time to close up since we're about to land at LAX.&amp;nbsp; Hope to see you at the launch event on Wednesday!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=855743" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPv6/default.aspx">IPv6</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category></item><item><title>WinServer "Longhorn" B3: This time it's "Ready, Set, (Download), and Evaluate!"</title><link>http://blogs.technet.com/ianhamer/archive/2007/04/25/winserver-longhorn-b3-this-time-it-s-ready-set-download-and-evaluate.aspx</link><pubDate>Thu, 26 Apr 2007 04:01:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:823287</guid><dc:creator>ianhamer</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/823287.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=823287</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=823287</wfw:comment><description>&lt;P&gt;That's right &lt;A href="http://www.microsoft.com/windowsserver/longhorn/default.mspx" mce_href="http://www.microsoft.com/windowsserver/longhorn/default.mspx"&gt;Windows Server "Longhorn"&lt;/A&gt; fans, Beta 3 is ready for your evaluation!&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Simply visit &lt;A href="http://www.microsoft.com/getbeta3" mce_href="http://www.microsoft.com/getbeta3"&gt;http://www.microsoft.com/getbeta3&lt;/A&gt;,&amp;nbsp;and you're halfway there to trying out the first major public preview of our next generation of Windows Server. &lt;/P&gt;
&lt;P&gt;As our press release touts:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#0000ff size=2&gt;"[With] Beta 3, customers will see new features and enhancements that include stronger security, better performance, new server roles and features, and additional server management and remote administration tools."&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;What that translates to is, well, a lot of new features and functionality that are ready&amp;nbsp;for "tire kicking."&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Heck, we even provided a little cheat sheet to help you zero in on some of the key new features:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;New and improved features in Beta 3 include the following:&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;Windows PowerShell is now included in the product.&lt;BR&gt;&lt;/FONT&gt;&lt;/EM&gt;
&lt;LI&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;A&lt;/FONT&gt;&lt;/EM&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;ctive Directory Federation Services improvements allow customers to implement new policies and make it easier to set up a relationship between trusted partners.&lt;BR&gt;&lt;/FONT&gt;&lt;/EM&gt;
&lt;LI&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;The Server Core installation option now comes with additional roles and enhanced functionality, such as print services and Active Directory Lightweight Directory Services.&amp;nbsp;&lt;BR&gt;&lt;/FONT&gt;&lt;/EM&gt;
&lt;LI&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;The Server Manager console includes additional remote administration tools to provide a more integrated management environment.&lt;BR&gt;&lt;/FONT&gt;&lt;/EM&gt;
&lt;LI&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;Windows Firewall with Advanced Security, now on by default, provides a persistent and more secure environment beginning at installation.&lt;BR&gt;&lt;/FONT&gt;&lt;/EM&gt;
&lt;LI&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#004080&gt;NAP is integrated with Microsoft Update and Windows Update to enable administrators to decide which updates are critical and set policies accordingly. It also has a new administrative interface for simplified setup, scalability and better performance.&lt;/FONT&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hey, there are two key features of mine on that list!&amp;nbsp; &lt;A href="http://www.microsoft.com/nap" mce_href="http://www.microsoft.com/nap"&gt;NAP&lt;/A&gt; and the &lt;A href="http://www.microsoft.com/technet/network/wf/default.mspx" mce_href="http://www.microsoft.com/technet/network/wf/default.mspx"&gt;Windows Firewall with Advanced Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Now, there's been enough written about that NAP thingy, so I'll concentrate on the Windows Firewall instead.&amp;nbsp; You didn't misread the bullet above -- we&amp;nbsp;have switched it on by default to help further the defense-in-depth&amp;nbsp;security controls&amp;nbsp;for Windows Server as well as help reduce attack surface area right out of the gate.&lt;/P&gt;
&lt;P&gt;We started down this road with&amp;nbsp;the "Post -Setup Security Update" feature in Windows Server 2003 Service Pack 1 that switched on the newly added Windows Firewall right after install so you could safely venture on to the Internet to retrieve latest updates without increasing the risk of an unpatched vuln being exploited over the network.&amp;nbsp; &amp;nbsp;As you might recall, this feature was described as follows:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#0000ff&gt;"Windows Firewall provides network protection after install while users update their system with the latest patches using the new Post-Setup Security Updates feature.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#0000ff&gt;[Post-Setup Security Updates was] designed to protect the server from the risk of infection between the time the server is first started and the application of the most recent security updates are applied from Windows Update. If Windows Firewall is enabled and the administrator did not explicitly enable Windows Firewall using an unattended-setup script or Group Policy, Post-Setup Security Updates opens the first time an administrator logs on."&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The team has been working diligently to test all the major Windows Server scenarios/workloads/roles/etc under this new "on by default" model to ensure we were able to map out the key IP service ports and related communication parameters.&amp;nbsp; We've also done some neat stuff with &lt;A href="http://technet2.microsoft.com/windowsserver/longhorn/en/servermanager/default.mspx" mce_href="http://technet2.microsoft.com/windowsserver/longhorn/en/servermanager/default.mspx"&gt;Server Manager&lt;/A&gt; feature (cool stuff!) to help apply the appropriate firewall policies per the role(s)/workload(s) you enable.&lt;/P&gt;
&lt;P&gt;I strongly encourage you to check this feature out, and learn about how this default to on works with the applications you run on top of Windows Server!&lt;/P&gt;
&lt;P&gt;Well, my battery is just about to die (I'm at SFO getting ready to head back to SEA from the &lt;A href="http://www.gartner.com/it/sym/2007/spg9/spg9.jsp" mce_href="http://www.gartner.com/it/sym/2007/spg9/spg9.jsp"&gt;Gartner Symposium/ITxpo&lt;/A&gt; event here this week -- more on that later), so I better stop here so I can get this thing posted!&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=823287" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Firewall/default.aspx">Windows Firewall</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPv6/default.aspx">IPv6</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Scalable+Networking/default.aspx">Scalable Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Secure+Wireless/default.aspx">Secure Wireless</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Networking/default.aspx">Windows Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>WinServer 2003 SP2 Comes Alive!</title><link>http://blogs.technet.com/ianhamer/archive/2007/03/13/winserver-2003-sp2-comes-alive.aspx</link><pubDate>Wed, 14 Mar 2007 02:35:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:692595</guid><dc:creator>ianhamer</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/692595.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=692595</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=692595</wfw:comment><description>&lt;p&gt;So.&amp;nbsp; Yes.&amp;nbsp; Okay.&amp;nbsp; I'm a &lt;a href="http://www.frampton.com/" target="_blank"&gt;Peter Frampton&lt;/a&gt; fan.&amp;nbsp; And, when I learned that our planned release of &lt;a href="http://www.microsoft.com/technet/windowsserver/sp2.mspx" target="_blank"&gt;Windows Server 2003 Service Pack 2&lt;/a&gt; (SP2) had, well, &lt;a href="http://blogs.technet.com/windowsserver/archive/2007/03/13/sp2-goes-live.aspx" target="_blank"&gt;released today&lt;/a&gt;, it made me think of Frampton's "&lt;a href="http://www.frampton.com/alive1.html" target="_blank"&gt;Frampton Comes Alive!&lt;/a&gt;" album from 1976.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Why?&amp;nbsp; &lt;/p&gt; &lt;p&gt;I don't know.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Seriously.&lt;/p&gt; &lt;p&gt;I did happen to go to &lt;a href="http://www.plattsburgh.edu" target="_blank"&gt;Plattsburgh State University&lt;/a&gt; (of New York) where several of the tracks were recorded (well before my tenure there).&amp;nbsp; Maybe that's it.&lt;/p&gt; &lt;p&gt;Moving on to the business at hand.&amp;nbsp; &lt;/p&gt; &lt;p&gt;WS03SP2 includes a bunch of stuff related to networking, including the following features:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://www.microsoft.com/snp" target="_blank"&gt;Scalable Networking Pack&lt;/a&gt; (TCP Chimney Offload, Receive-side Scaling and NetDMA)&lt;br&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://www.microsoft.com/ipsec" target="_blank"&gt;IPsec&lt;/a&gt; &lt;a href="http://support.microsoft.com/default.aspx/kb/914841/en-us" target="_blank"&gt;Simple Policy Update&lt;/a&gt; (aka &lt;strong&gt;&lt;em&gt;Improved IPsec filter management&lt;/em&gt;&lt;/strong&gt;) for making &lt;a href="http://www.microsoft.com/sdisolation" target="_blank"&gt;Server and Domain Isolation&lt;/a&gt; deployments easier with WS03 and XP&lt;br&gt;&lt;/li&gt; &lt;li&gt;Wi-Fi Protected Access 2 (WPA2) support for XP x64 and WS03&lt;br&gt;&lt;/li&gt; &lt;li&gt;Enabling ‘Firewall Per Port’ Authentication which means "&lt;em&gt;Firewall per port authentication secures traffic between the Extranet environment and internal assets that are protected via IPsec Domain Isolation.&lt;/em&gt;"&lt;/li&gt;&lt;/ul&gt; &lt;p align="left"&gt;And, there's a whole lot more that makes Server Pack 2 worth a good look and eventual deployment.&lt;/p&gt; &lt;p align="left"&gt;&lt;strong&gt;"So, how do I get it?"&lt;/strong&gt;&lt;/p&gt; &lt;p align="left"&gt;It's already available off of Windows Update/Microsoft Update.&amp;nbsp; At first (as pictured below) it was placed under the High-priority updates, but it is now a "Software, Optional".&amp;nbsp;&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/WinServer2003SP2ComesAlive_E92E/WS03SP2%5B3%5D.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="370" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/WinServer2003SP2ComesAlive_E92E/WS03SP2_thumb%5B3%5D.png" width="450" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Nevertheless, we'll be making this an automatic update in the a few months, much like we did with Windows Server 2003 SP1 and XP SP2.&amp;nbsp; &lt;/p&gt; &lt;p&gt;You can also visit the official SP2 site on TechNet and find all different versions of the SP for WS03 and XP x64 Edition:&lt;/p&gt; &lt;p align="center"&gt;&lt;a title="http://www.microsoft.com/technet/windowsserver/sp2.mspx" href="http://www.microsoft.com/technet/windowsserver/sp2.mspx"&gt;&lt;strong&gt;http://www.microsoft.com/technet/windowsserver/sp2.mspx&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; &lt;p align="left"&gt;The above link includes links the downloads (regular and ISO flavors),&amp;nbsp;overview docs, like the&amp;nbsp;&lt;a href="http://www.microsoft.com/technet/windowsserver/sp2/overview.mspx" target="_blank"&gt;overview&lt;/a&gt; and &lt;a href="http://go.microsoft.com/fwlink/?LinkId=62452" target="_blank"&gt;what's new in SP2&lt;/a&gt;, and deployment guidance.&amp;nbsp; There's also a great "&lt;a href="http://www.microsoft.com/technet/windowsserver/sp2/top-reasons.mspx" target="_blank"&gt;Top 10 Reasons to Install&lt;/a&gt;" which happens to feature two of my favorites as #3 and #4:&lt;/p&gt; &lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/WinServer2003SP2ComesAlive_E92E/top10%5B4%5D.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="352" src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/WinServer2003SP2ComesAlive_E92E/top10_thumb%5B4%5D.png" width="500" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Download SP2 and start evaluating.&amp;nbsp; Especially since the &lt;a href="http://www.microsoft.com/windowsserver/longhorn/deployment/services.mspx" target="_blank"&gt;WDS&lt;/a&gt; features will help you get Windows Vista deployed and, well, heck, it's got a lot of networking goodness to keep you happy while we finish up Windows Server "Longhorn".&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=692595" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Firewall/default.aspx">Windows Firewall</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Scalable+Networking/default.aspx">Scalable Networking</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Windows+Server+2003/default.aspx">Windows Server 2003</category></item><item><title>Keep Unsecured Machines Off Your Network (A WinIT Pro Podcast)</title><link>http://blogs.technet.com/ianhamer/archive/2007/02/26/keep-unsecured-machines-off-your-network-a-winit-pro-podcast.aspx</link><pubDate>Mon, 26 Feb 2007 23:26:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:663469</guid><dc:creator>ianhamer</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/ianhamer/comments/663469.aspx</comments><wfw:commentRss>http://blogs.technet.com/ianhamer/commentrss.aspx?PostID=663469</wfw:commentRss><wfw:comment>http://blogs.technet.com/ianhamer/rsscomments.aspx?PostID=663469</wfw:comment><description>&lt;P&gt;A couple of weeks ago, I had the opportunity to sit down with &lt;A href="http://www.windowsitpro.com/Authors/AuthorID/126/126.html" target=_blank mce_href="http://www.windowsitpro.com/Authors/AuthorID/126/126.html"&gt;Karen Forster&lt;/A&gt; of &lt;A href="http://www.windowsitpro.com/" target=_blank mce_href="http://www.windowsitpro.com/"&gt;Windows IT Pro&lt;/A&gt; magazine to record a podcast about a whole slew of things related to our network security solutions (aka policy-driven network access solutions):&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.windowsitpro.com/podcast/Index.cfm?fuseaction=ShowRegistration&amp;amp;PCID=ffebb6d4-e086-4a0f-9980-c5efe17b0424" target=_blank mce_href="http://www.windowsitpro.com/podcast/Index.cfm?fuseaction=ShowRegistration&amp;amp;PCID=ffebb6d4-e086-4a0f-9980-c5efe17b0424"&gt;Keep Unsecured Machines Off Your Network: Microsoft Talks About Policy-Driven Network Access Solutions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Here's the synopsis Karen wrote to describe our 20 minute chat:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT face="Courier New" color=#0000ff&gt;Imagine your network protecting itself by preventing unsecured devices from accessing your resources. Microsoft is now providing technology that ensures every device that connects to your network has up-to-date security protection (e.g., current patches, anti-virus and anti-spyware). You can keep machines that are not compliant with your security policies off your network with Network Access Control (NAC) technologies for Longhorn Server and Windows Vista. Karen Forster discusses Microsoft's recent announcements about NAC, as well as Network Access Protection (NAP), with Microsoft's Ian Hameroff. Learn how NAC and NAP work and what technologies are involved, as well as what third-party products are poised to work with these technologies, in this exclusive interview.&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The chat covers things like &lt;A href="http://www.microsoft.com/sdisolation" target=_blank mce_href="http://www.microsoft.com/sdisolation"&gt;Server and Domain Isolation&lt;/A&gt; and &lt;A href="http://www.microsoft.com/nap" target=_blank mce_href="http://www.microsoft.com/nap"&gt;Network Access Protection&lt;/A&gt;, as well as &lt;A href="http://www.microsoft.com/Presspass/exec/billg/speeches/2007/02-06RSA.mspx" target=_blank mce_href="http://www.microsoft.com/Presspass/exec/billg/speeches/2007/02-06RSA.mspx"&gt;Bill and Craig's keynote from RSA 2007&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Since the recording of the podcast, we've taken a big leap forward in our internal deployment of NAP (aka "The Pilot").&amp;nbsp; We're now up and running across very large (10s of thousands clients) swaths of our network here in Redmond and MSIT is already seeing benefit from the policy-enforcement mechanisms.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;For example, I attempted to shutdown my antivirus real-time scanner service&amp;nbsp;and was immediately dinged by NAP:&lt;/P&gt;
&lt;P align=center&gt;&lt;A href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/KeepUnsecuredMachinesOffYourNetworkAWinI_AEE1/nap-popup%5B2%5D.png" mce_href="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/KeepUnsecuredMachinesOffYourNetworkAWinI_AEE1/nap-popup%5B2%5D.png"&gt;&lt;IMG style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" height=306 src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/KeepUnsecuredMachinesOffYourNetworkAWinI_AEE1/nap-popup_thumb%5B2%5D.png" width=450 border=0 mce_src="http://blogs.technet.com/blogfiles/ianhamer/WindowsLiveWriter/KeepUnsecuredMachinesOffYourNetworkAWinI_AEE1/nap-popup_thumb%5B2%5D.png"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P align=left&gt;As soon as I restarted the service, I was deemed healthy and carried on with no issues.&amp;nbsp; The neat thing with the fact the NAP agent is built into Windows Vista (we're running Windows Vista Enterprise) is I did not need to install any software or anything.&amp;nbsp; In fact, I didn't even know that the "switch had been thrown" until my manager sent out a note stating such.&lt;/P&gt;
&lt;P align=left&gt;Anyhow, checkout this podcast and let me know if you have any questions!&lt;/P&gt;
&lt;P align=left mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=663469" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ianhamer/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Server+and+Domain+Isolation/default.aspx">Server and Domain Isolation</category><category domain="http://blogs.technet.com/ianhamer/archive/tags/Network+Access+Protection/default.aspx">Network Access Protection</category></item></channel></rss>