VPN Internet routing problem
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > WebserverTalk Community > VPN > VPN Internet routing problem




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    VPN Internet routing problem  
ioevanc@gmail.com


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-06 02:22 AM

Hello

I have a Windows Server 2003 configured as a remote access VPN server.
Everything works perfectly, however when I connect from a client
machine to the VPN my internet connection get taken over by the
server's internet connection, anotherwords, not only it is routing my
LAN but also the internet connection the server is on.

Is it possible not to have the internet routed, just the LAN ? But
still be able to use client's internet connection ?

Thanks






[ Post a follow-up to this message ]



    Re: VPN Internet routing problem  
Martin Bodenstedt


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-06 02:22 AM

ioevanc@gmail.com schrieb:
> Hello
>
> I have a Windows Server 2003 configured as a remote access VPN server.
> Everything works perfectly, however when I connect from a client
> machine to the VPN my internet connection get taken over by the
> server's internet connection, anotherwords, not only it is routing my
> LAN but also the internet connection the server is on.

This by design.

Once your VPN connection is open the VPN client should only allow
traffic through the tunnel for security reasons (keyword here is "Split
tunneling").

This also means that once Your PC has the VPN connection open the pc
cannot see the lan anymore (to protect the corporate network from being
infiltrated by rogue pcs...


--
Martin Bodenstedt

(www.die-bodenstedts.de / www.maboko.de)





[ Post a follow-up to this message ]



    Re: VPN Internet routing problem  
Simon


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-06 02:22 AM

Martin Bodenstedt wrote:
> ioevanc@gmail.com schrieb:
> 
>
>
> This by design.
>
> Once your VPN connection is open the VPN client should only allow
> traffic through the tunnel for security reasons (keyword here is "Split
> tunneling").
>
> This also means that once Your PC has the VPN connection open the pc
> cannot see the lan anymore (to protect the corporate network from being
> infiltrated by rogue pcs...
>
>
Martin is correct, however I'm sure you can still see the local subnet
Martin, it's only the default route that's affected.

With the windows client you can get round it though if you consider the
risks worthwhile, here's what I posted the other day in response to a
similar question
"Yes it's a security risk if the remote computer becomes compromised, as
the internet connection going out locally could allow a back door into
your network when the client vpn is connected. However with the ms
client you can open up split routing to do what you need, in the tcpip
properties of the remote PCs connection to you under advanced untick the
'use default gateway on remote network' then only traffic destined for
the subnet that the client vpn address gets goes down the tunnel, all
else goes out locally. If there is more than one subnet at your location
the remote clients would need to use the route add command to add the
additional routes needed. "
simon





[ Post a follow-up to this message ]



    Re: VPN Internet routing problem  
ioevanc@gmail.com


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-06 02:22 AM

Thanks for your help, I apreciate it

Simon wrote:
> Martin Bodenstedt wrote: 
> Martin is correct, however I'm sure you can still see the local subnet
> Martin, it's only the default route that's affected.
>
> With the windows client you can get round it though if you consider the
> risks worthwhile, here's what I posted the other day in response to a
> similar question
> "Yes it's a security risk if the remote computer becomes compromised, as
> the internet connection going out locally could allow a back door into
> your network when the client vpn is connected. However with the ms
> client you can open up split routing to do what you need, in the tcpip
> properties of the remote PCs connection to you under advanced untick the
> 'use default gateway on remote network' then only traffic destined for
> the subnet that the client vpn address gets goes down the tunnel, all
> else goes out locally. If there is more than one subnet at your location
> the remote clients would need to use the route add command to add the
> additional routes needed. "
> simon






[ Post a follow-up to this message ]



    Re: VPN Internet routing problem  
ioevanc@gmail.com


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-06 02:22 AM

Thanks for your help !






[ Post a follow-up to this message ]



    Re: VPN Internet routing problem  
Martin Bodenstedt


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
01-14-06 02:22 AM

Simon schrieb:

> Martin is correct, however I'm sure you can still see the local subnet
> Martin, it's only the default route that's affected.

That should not be the case as all local pcs (those in the same subnet)
could still use the tunnel which I as a corporate network admin would
never tolerate.

A good vpn client permits no traffic through the tunnel other than from
(or to) the local machine itself.



--
Martin Bodenstedt

(www.die-bodenstedts.de / www.maboko.de)





[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 10:16 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register