Modify the authentication method for the IPSec policy on FILE3 to require a certificate and install certificates on all client computers in the Research OU.
Reconfigure the IPSec policy for FILE3 to use the Server (Request Security) IPSec policy.
Configure the key exchange settings for the IPSec policy on FILE3 to use Master key Perfect Forward Secrecy (PFS).
Create a Group Policy object (GPO) that assigns the Secure Server (Require Security) to the Research OU.