The deployment of IPsec enforcement consists of the following tasks:
Configuring Active Directory
Configuring NAP health policy servers
Configuring remediation servers on the boundary network
Configuring NAP clients
Configuring and applying IPsec policies
To configure Active Directory for IPsec enforcement, do the following:
Add an IPsec exemption group for computers in the boundary network.
Create groups or OUs for boundary and secure network computers.
In the console tree of the Active Directory Users And Computers snap-in, right-click your domain name, point to New, and then click Group.
In the Group Name box, type the name (such as ...