"Soft Associations" Between IPSec-Enabled and Non-IPSec-Enabled Computers (234580)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Datacenter Server
This article was previously published under Q234580 SUMMARY
This article describes how to allow or prevent communication between secure and unsecured computers.
The IP Security (IPSec) Policy's negotiation policy can either allow or disallow unsecured traffic. When two computers that support IPSec communicate with each other, they establish security associations that are determined through negotiation of the Internet Security Association and Key Management Protocol (ISAKMP) and IPSec Policy rules. If either of two computers does not support IPSec, they must communicate without security, which is called a "soft association". Downlevel clients do not support IPSec communication and cannot communicate unless soft associations are permitted.
Modification Type: | Major | Last Reviewed: | 11/21/2003 |
---|
Keywords: | kbenv kbinfo KB234580 |
---|
|