Re: RAS'd in : why traffic sent through VPN router ?



I see this as a trade-off issue with 3 angles:

1. performance: yes, minor incovenience when hitting google, but that's the
fastest site on earth. Other sites can go from 1-2 sec when routed via local
inet gateway to 10+ secs when routed through remote VPN inet gateway. This
eventually adds up to a significant loss in productivity. I know of a
company where 50%+ employees have two boxes (typically one laptop, one
desktop). One box is RAS'd in to the client's VPN; the other is not and is
used for all web research.

2. security : if all client-originating inet traffic routes bidirectionally
through a better firewall, then yes security is improved. When connecting
home office to workplace VPN, I see security issues as a reasonable argument
for "Use default gateway on remote network". However, when connecting from
one highly secure workplace environment to the VPN of another highly secure
workplace envionment, I don't see the benefit -- unless one environment is
proven to be significantly more secure than the other.

3. system failures : in the workplace case, where Outlook points to an
Exchange Server (ES) on the local network, Outlook can easily become
locked-up trying to locate its ES on the VPN. This can sometimes require
killing the Outlook process; and sometimes it even requires hard rebooting
the machine. This can kill a good 15 mins restarting all the apps, RAS'ing
in again, starting the apps on the VPN, etc.


"Lanwench [MVP - Exchange]"
<lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:eoxwrEDXGHA.3760@xxxxxxxxxxxxxxxxxxxxxxx


In news:OPRw7M5WGHA.5096@xxxxxxxxxxxxxxxxxxxx,
John A Grandy <johnagrandy-at-yahoo-dot-com> typed:
Why is it when RAS'd into a VPN that a much of your network traffic
gets routed through the inet router of the VPN ?

In addition to Robert's reply (regarding 'use remote gateway'), you really
don't want anyone connecting to the compny network from their own
(possibly insecure) networks via VPN, unless all non-VPN traffic is
disabled at the time.


I'm not talking the case where you are Remote Desktop'd into a
machine that part of the VPN's network.

I'm talking having the the case of having VPN connection open, and the
following two types of requests:

1. Making simple browser requests from your box to public websites:
google.com , whatever. If you look at the tracert and you see that
the VPN's network's router and then it's inet provider is forwarding
the packets. This slows down speed of web access.

Perhaps, but I think it's worth the minor inconvenience given the security
issues opened up if you *don't* use remote gateway.

2. When Outlook needs to contact its assigned Exchange Server it
tries to find it on the VPN's network ! Incredibly annoying. You
can see Outlook popping up message boxes above the systray saying
it's unable to find it's Exchange Server.

Well, where *is* the Exchange server, and how do you connect to it?


Can XP Pro SP2 be confi'd so that it knows to first go to the local
network and the local router for requested urls, including local
network resources ?

Yes; it's 'use remote gateway', but if the IT staff responsible for the
remote network care about security, they won't allow that to work.



.



Relevant Pages

  • RE: Remote desktop over a VPN
    ... I understand the issue to be: you have created VPN ... from SBS to remote network, however you can not VPN to remote network from ... This issue may occur because the ISA Server Firewall Client program does ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote User Management
    ... The problem is management of remote computers and compliance ... when they do not have network ... We have been considering installing Site-Link VPN appliances at the ... establish connectivity to domain resources. ...
    (microsoft.public.windows.server.active_directory)
  • Re: VPN Connection to remote site.
    ... If you need further assistance about SBS and ISA in the future, please feel free to post back. ... >Subject: Re: VPN Connection to remote site. ... >problematic and we found that the EPOS PC tended to drop off the network ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote site browsing and file access
    ... than routing typically causes for remote netbios name resolution). ... -- uses software VPN to connect 10.10.0.0/255.255.248.0 network to remote ... -- Server provides all local DNS and DHCP ...
    (microsoft.public.windows.server.sbs)
  • Re: [fw-wiz] Benefits of Network Extention Mode vs IPsec
    ... "Network Extension Mode" is Cisco-specific terminology, ... you're talking about Cisco VPN gear. ... One of the big problems for IPsec deployments is making sure that the VPN ... For remote access VPNs, where you've typically got a single machine ...
    (Firewall-Wizards)