Re: Security over VPN

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/03/04


Date: Sat, 03 Jul 2004 23:30:18 GMT

I am not familiar with the devices that you use but check their configuration to see
if they can restrict access of the vpn tunnel to only certain IP addresses on the
lan. If you are using the W2K server as the vpn server, you can configure packet
filters on the IP interface in rras or in Remote Access Policy. Another alternative
is to configure ipsec policy with either negotiation for ESP/AH protection which uses
kerberos machine authentication in the forest or ipsec filtering to limit access to
what IP addresses can access a computer via permit and block filter actions. ---
Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;310111 --- shows about
packet filtering.
http://www.securityfocus.com/infocus/1559 --- ipsec filtering

"Jeff Li" <anonymous@discussions.microsoft.com> wrote in message
news:2597701c460ae$a17398a0$a401280a@phx.gbl...
> Hi all,
>
> I built up a VPN b/w head office and branch office by a
> pair of VPN devices (zyxel). Both-end are Windows 2000
> Server. The VPN's objective is that I want the branch
> office access the Web application in headoffice's server
> only. The headoffice's server is also file server and
> domain controller. What can I do so that the branch
> office cannot browse computer(headoffice) and shared
> folder in headoffice?
>
> Regards
>
> Jeff Li



Relevant Pages

  • Re: Using 2000 SBS on a 2003 Standard Domain
    ... filtering on top of all of the other SBS functions & we are running out ... is add a new Windows 2003 Standard Edition Server as the PDC to do AD, ... DHCP, DNS, VPNs Print and File sharing and then keep the 2000 SBS ... As for the rest, DHCP and DNS are trivial in terms of load, VPN belongs with ISA which must remain on the SBS, which only really leaves File&Print services, another relatively trivial load. ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN Connection Problems
    ... Note that we are able to successfully VPN into the office. ... to browse the network, RDP to the server or even ping the server. ... > This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN issue on SBS2003
    ... I understand that you encountered VPN connection issue when you use VPN to ... Internet clients or VPN to external VPN Server from SBS Client computers? ... Configure E-mail and Internet Connection Wizard ... Total GRE packets sent = 1 ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA2004 kills VPN outbound
    ... Extract all files to a folder on ISA server. ... Expand the server node and highlight 'Monitoring'. ... After the VPN connection was established, ... |> Since the branch office workstations can connect to the VPN server, ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows 2003 VPN Default Gateway Issues
    ... on the same subnet as the server leads me to believe it was a routing ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com ... the default gateway on the client is not the problem. ...
    (microsoft.public.windows.server.networking)