69
Intersite Messaging
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
IsmServ
Disabled (Started for
a domain controller)
Disabled Disabled Disabled
The
Intersite Messaging
system service enables messages to be exchanged between computers
running Windows Server sites. This service is used for mail-based replication between sites. Active
Directory includes support for replication between sites by using SMTP over IP transport. These
features are not required in the baseline server environment. Therefore, this service is configured to
Disabled.
This service is, however, required on domain controllers. For this reason, the
Intersite
Messaging
service is set to
Automatic
on the domain controllers in the three environments defined in
this guide.
IP Version 6 Helper Service
Service Name
Member Server
Default
Legacy Client
Enterprise Client High Security Client
6to4 Not
installed
Disabled Disabled Disabled
Important: IP Version 6 Helper Service
must be set to
Automatic
for HP NAS server systems requiring
IPv6 support.
The
IP Version 6 Helper Service
system service offers IPv6 connectivity over an existing IPv4 network.
These features are not required in the baseline server environment. Therefore, this service is
configured to
Disabled.
IPSEC Policy Agent (IPSec Service)
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
PolicyAgent Automatic
Automatic Automatic Automatic
The
IPSEC Policy Agent
service provides end-to-end security between clients and servers on TCP/IP
networks. It also manages IP security (IPSec) policy, starts the Internet Key Exchange (IKE), and
coordinates IPSec policy settings with the IP security driver. This service is enabled in the three
environments defined in this guide.
Kerberos Key Distribution Center
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
Kdc Disabled Disabled Disabled Disabled
The
Kerberos Key Distribution Center
system service enables users to log on to the network by using
the Kerberos v5 authentication protocol. For these reasons, set the value for this service to
Automatic
in the domain controllers’ policy.