Re: Possible security implications when using VPN and XP Client



Hi Tommy,

Windows VPN client is not part of ISA, it is part of Windows OS. So this
questions belongs to RAS.

I am not sure I understand your concern. As far as I can see this, there is
not a security hole - if user changes this property, he can achieve the same
would he just disconnected VPN connection - he will be connected back to the
Internet.

---------------------------------------------------------------------------
"This posting is provided "AS IS" with no warranties, and confers no
rights."


"Tommy" <Tommy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:739A81B0-C405-40DC-AD80-039306F7D39F@xxxxxxxxxxxxxxxx
Hi,

I have set up ISA Server as our VPN server which my remote users access.
On each of the clients (using XP) we use the standard VPN connection that
you can setup from the Network Connections section.

When that connection is setup and the connection is made, this then
restricts browser communications to the local office network only (regular
internet activity stops working unless the Firewall Client is installed)

However, I have discovered that by editing the VPN connection on the
client,
by editing the TCP-IP Advanced properties, I can deselect the "use default
gateway on remote network" option - this then allows internet browsing to
work when connected via to the VPN server.

Is this a security loophole in any way? When I was learning ISA Server, it
was always emphasised that ISA server stops this kind of thing to keep
security tight.

Can anyone shed any light on this?

Thanks

Tommy Addison


.



Relevant Pages

  • Re: Outgoing VPN Error 619
    ... Outbound VPN problem: ... Q1 - is the test client configured as SecureNET? ... Q2 - what do you find in the ISA logs for your tests? ... I've checked in local network rules and I do have a rule called VPN clients ...
    (microsoft.public.isa.vpn)
  • RE: VPN timeouts
    ... I do not use ISA & was wondering if there is a configurable option on the ... You remote clients VPN connection will timeout while trying to connect SBS ... between remote client and SBS server which caused by lack of network ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN connection
    ... I understand that when you try to establish a VPN ... connection from a remote client, the connection terminated in the process ... Please temporarily place a client directly connected to the external NIC ... of the SBS Server. ...
    (microsoft.public.windows.server.sbs)
  • RE: Problems with connectcomputer and active directory
    ... I understand that you would like to join a remote client to the domain. ... If you have hardware VPN tunnel setup using Linksys or others, ... In this scenario you have to configure the SBS Server computer to enable ... Create a VPN connection to ISA/RRAS on the Internet ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA2004 kills VPN outbound
    ... I understand that after you upgraded ISA 2000 to ISA ... 825763 How to configure Internet access in Windows Small Business Server ... Then, establish the VPN connection again, does it work this time? ... FW client and configure the client as a SecureNAT client. ...
    (microsoft.public.windows.server.sbs)