Skip to content

Commit 836ea9a

Browse files
authored
Update Enable-NetIPsecRule.md
Updating the details in -KeyModule parameter to reflect changes in the code for how this value is set, and set this information to be consistent across all the relevant documentation pages that reference it.
1 parent e237b6a commit 836ea9a

File tree

1 file changed

+6
-9
lines changed

1 file changed

+6
-9
lines changed

docset/winserver2022-ps/netsecurity/Enable-NetIPsecRule.md

Lines changed: 6 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -629,15 +629,12 @@ Specifies that matching IPsec rules of the indicated key module are enabled.
629629
This parameter specifies which keying modules to negotiate.
630630
The acceptable values for this parameter are: Default, AuthIP, IKEv1, or IKEv2.
631631
632-
- Default: Equivalent to both IKEv1 and AuthIP.
633-
Required in order for the rule to be applied to computers running Windows versions prior to nextref_server_7.
634-
---- There are authorization and cryptographic methods that are only compatible with certain keying modules.
635-
This is a very advanced setting intended only for specific interoperability scenarios.
636-
Overriding this parameter value may result in traffic being sent in plain-text if the authorization and cryptographic settings are not supported by the keying modules there.
632+
- Default: KeyModule is set based on the authentication method. As of Win11 24H2 and Server 2025, the Default is equivalent to both IKEv1 and IKEv2, and only sets AuthIP if the authentication method(s) require it. In previous releases, Default is equivalent to both IKEv1 and AuthIP. Required in order for the rule to be applied to computers running Windows versions prior to Server 2008.
637633
- AuthIP: Supported with phase 2 authentication.
638-
- IKEv1: Supported with pre-shared key (PSK), Certificates, and Kerberos.
639-
- IKEv2: Not supported with Kerberos, PSK, or NTLM.
640-
Windows versions prior to Windows Server 2012 only support the Default configuration.
634+
- IKEv1: Supported with pre-shared key (PSK), Certificates, and Kerberos. Supported with phase 1 authentication only.
635+
- IKEv2: Not supported with Kerberos, PSK, or NTLM. Supported with phase 1 authentication only.
636+
637+
The default value is Default. There are authentication and cryptographic methods that are only compatible with certain keying modules. This is a very advanced setting intended only for specific interoperability scenarios. Overriding this parameter value may result in traffic being sent in plain-text if the authorization and cryptographic settings are not supported by the keying modules. Windows versions prior to Windows Server 2012 only support the Default configuration.
641638
642639
```yaml
643640
Type: KeyModule[]
@@ -647,7 +644,7 @@ Accepted values: Default, IKEv1, AuthIP, IKEv2
647644

648645
Required: False
649646
Position: Named
650-
Default value: None
647+
Default value: Default
651648
Accept pipeline input: False
652649
Accept wildcard characters: False
653650
```

0 commit comments

Comments
 (0)