http://support.microsoft.com/kb/920074
http://technet.microsoft.com/en-us/library/cc784300%28v=ws.10%29.aspx
Stopping and restarting the IPSec service
Stopping and restarting the IPSec service can disconnect all of the computers that are using IPSec from the computer on which the IPSec service is stopped, and it can prevent further communication with that computer. However, if you restart the IPSec service immediately, TCP-based communication might resume, due to the retransmit behavior of TCP, after new IKE and IPSec SAs are established. If you leave the IPSec service stopped, any clients that used the default response rule to establish security will be unable to communicate with this computer for two hours.
To avoid losing Terminal Services connectivity for computers that are using IPSec over a Terminal Server session, you must stop and restart the IPSec service by using a single command line:
- To stop and restart the IPSec service for computers over a Terminal Server session
- At the command prompt, type the following:
net stop policyagent & net start policyagent
If you are restarting the IPSec service on a computer that is running the Windows Server 2003 family or the Windows Server 2003 family and that is also running the Routing and Remote Access service, any IPSec configuration for L2TP will be lost and the L2TP tunnels will be disconnected. Therefore, you must stop and restart the Routing and Remote Access service, as well as the IPSec service.
To stop and restart the IPSec service and the Routing and Remote Access service, do the following:
- Stop the Routing and Remote Access service using the net stop remoteaccess command.
- Stop the IPSec service by using the net stop policyagent command.
- Start the IPSec service by using the net start policyagent command.
- Start the Routing and Remote Access service using the net start remoteaccess command.


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Back to top







