Re: Routing remote client internet traffic thru VPN

From: Bill Grant (not.available_at_online)
Date: 12/03/04


Date: Sat, 4 Dec 2004 08:34:43 +1100


    That is certainly the case with a proxy server setup. For a W2k/XP
client, proxy settings are connection specific. So to use a proxy server
over a RAS/VPN connection, you need to set the proxy settings for the
connection. You can do it from Control Panel | internet options. This allows
you to have different proxy settings for local and remote proxy servers.

"Lunchb0x" <johnpitton@hotmail.com(donotspam)> wrote in message
news:0AA47893-6D0D-4B60-8304-3AF7479A3EB4@microsoft.com...
>I had a similar issue but I'm not using an ISA server. I instead have a
> seperate firewall that I wanted VPN clients to pass through when VPNing
> in.
> This is for security reasons and allow the ability for users to access the
> internet while VPNed into my network WITHOUT using split tunneling. With
> that said here is how I resolved it.
> On the client I selected "use default gateway on remote network" for the
> TCP/IP properties on the VPN connection. I then had them modify their IE
> settings for the VPN connection to point them to my network's proxy
> server(firewall) using port 80 (this could be different depending on your
> firewall setup) for all internet protocols (HTTP, FTP, Gopher, etc).
> After
> this was done, clients could then reach all internal routeable subnets
> along
> with accessing the internet. Here's a good link with pretty pictures on
> setting this up:
> http://www.isaserver.org/tutorials/Solving_the_Mystery_of_the_VPNRASWeb_Proxy_Client.html
>
> cheers,
> Lunchb0x
>
> "Dean Macinskas" wrote:
>
>> Hello,
>>
>> I have installed RRAS on my Win2K server and client, and can establish a
>> VPN
>> from my remote client and see the internal server's resources. But I
>> also
>> want to route my client's internet traffic (browsing and mail) through
>> the
>> VPN and have my RRAS server fire off the packets to and from the office
>> DSL
>> router (the purpose here is to secure my internet traffic through the
>> VPN).
>> The problem seems to be that when I first establish an internet
>> connection
>> from the client I get a default gateway pointing to the IP address given
>> me
>> by whatever ISP I'm connecting to, and there is no default gateway
>> associated with the VPN connection; the result is that internet traffic
>> automatically bypasses the VPN in favor of the direct connection. So, I
>> guess I have two questions:
>> 1.. Is doing what I want to do even possible?
>> 2.. If the answer above is 'yes', how do I go about establishing the
>> appropriate routes? I've searched the MS Knowledge Base, and although
>> I've
>> seen a few hints I cannot find a procedure that works. I cannot find any
>> way to define a default gateway in the standard VPN 'Properties' windows.
>> Thanks for your help.
>>
>> Regards,
>> Dean P. Macinskas
>>
>>
>>



Relevant Pages

  • Re: Rerouting Requests via a Proxy because of .NET "bug"
    ... >> corporate client who forces their workstations to get the proxy server ... >> details using an automatic proxy discovery script. ... > between the client and the server. ... discovery script to determine the proxy server settings. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Rerouting Requests via a Proxy because of .NET "bug"
    ... >> corporate client who forces their workstations to get the proxy server ... >> details using an automatic proxy discovery script. ... > between the client and the server. ... discovery script to determine the proxy server settings. ...
    (microsoft.public.dotnet.framework.webservices)
  • RE: Erratic SSL Error: Could not establish secure channel for SSL/TLS
    ... keep-alives in the generated .NET proxy client. ... so it tries to use a dead connection. ... proxy from making a request with keep-alives enabled. ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: Remote Desktop Web Connection through a Proxy Server
    ... Do you mean that the Firewall at the proxy might be blocking the port? ... Remote connection, the Port used by the Remote program has to be forwarded ... There is a proxy server which provides us with internet connection at ...
    (microsoft.public.windowsxp.network_web)
  • Re: Proxy capabilities and securenat/firewall client
    ... I currently have a watchguard box as my perimeter firewall. ... public IP) in order to utilise it's reverse web proxy functionality. ... Connection. ... IPSEC firewall client? ...
    (microsoft.public.isaserver)