<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://port25.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Server &amp;amp; Domain Isolation with Fernando Cima, Microsoft Brazil (Podcast)</title><link>http://port25.technet.com/archive/2006/07/07/Server-_2600_-Domain-Isolation-with-Fernando-Cima_2C00_-Microsoft-Brazil-_2800_Podcast_2900_.aspx</link><description>Sam talks with Fernando Cima from Microsoft Brazil's Security Center of Excellence about the challenges and progress being made in securing and maintaining today's mixed network environments. More specifically, the focus in this discussion is on Server</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 40109.1145)</generator><item><title>More information</title><link>http://port25.technet.com/archive/2006/07/07/Server-_2600_-Domain-Isolation-with-Fernando-Cima_2C00_-Microsoft-Brazil-_2800_Podcast_2900_.aspx#2721</link><pubDate>Mon, 10 Jul 2006 13:33:22 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2721</guid><dc:creator>fernando_cima</dc:creator><description>Thanks Jamie, Sam and the CTAC crew for the opportunity for this podcast. I'd like to add a little bit more of information to our readers:&lt;br&gt;&lt;br&gt;IPsec is usually associated with VPN, and sometimes people don't realize that it can be used to protect &amp;quot;regular&amp;quot; network traffic inside a corporate or home network. This is basically what Domain Isolation is about: using IPsec in transport mode to authenticate and sometimes also encrypt trusted network traffic, while discarding traffic from untrusted sources.&lt;br&gt;&lt;br&gt;This is a solution that has been in use in Microsoft corporate network for some years, and when we took it to customers there was a clear need for interoperability. So our group (me and my colleague Kiyoshi Watanabe from Japan) started working on creating guidance for using the solution with Linux, FreeBSD, Mac OS X, Solaris and other platforms.&lt;br&gt;&lt;br&gt;The beauty of it is that every modern OS has IPsec and IKE support, and even though not all IPsec implementations are created equally, all the platforms we tested have been working quite well. As long as you have IPsec and IKE support, with PKI authentication, and is able to define remote IPs/subnets where IPsec should not be used, you are good to go.&lt;br&gt;&lt;br&gt;Our guide is currently being formatted and going through the legal and technical review, and should be posted to &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/sdisolation"&gt;http://www.microsoft.com/sdisolation&lt;/a&gt; as soon as it is ready. We are sorry for not having it on time for the podcast, but in the meantime I'd be glad to answer any question that our readers might have!&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2721" width="1" height="1"&gt;</description></item></channel></rss>