VPN issues

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Tom M (tmcnally_at_mdl.com)
Date: 01/21/05


Date: Fri, 21 Jan 2005 08:22:16 -0600

Have a small Windows 2003 network with XP Prof SP2 workstations. I have
very little GPO entries applied in both the Domain Computer and Domain Group
Policy beyond the basic defaults. No OUs yet applied (this is basically a
test network). DNS and Active Directory resolve fine normally.

Several of the workstations connect to a VPN using a proprietary AT&T
IPSec-based cardkey entry system -- provided by the client. While I can
connect fine and receive my VPN IP ok, when the GPO is enforced on the
network the redirected scripting (in the connection area of MSIE) to the
host server is blocked and I get nothing in a browser. DNS and WINs server
entries are all applied in the NIC card, so it seems to be resolving ok. I
can create a remote desktop connection to the client without problem. Just
nothing of course in the web area. When I don't enforce the GPO links, all
works ok, so it's something with my network's group policy setup that is
inhibiting this redirection action.

When I'm on the VPN tunnel access to my internal network, shared drives etc,
is restricted due to their security policy, and I assume my group policy is
halted as well, but not before the VPN connection is made. My domain is of
course not trusted on theirs.

Any idea what entry in group policy could be blocking this?

Thanks for any assistance,

Tom



Relevant Pages

  • Re: Cached GPOs
    ... seen to caching occurs when you're editing a GPO. ... Template policy to ... > It may have been that at one time when the users were off network they ... >>> would still have the screen saver tab hidden because none ...
    (microsoft.public.windows.group_policy)
  • Re: EventID 1054 from Userenv for startup script
    ... This order means that the local GPO is processed first, and GPOs that are linked to the organizational unit of which the computer or user is a direct member are processed last, which overwrites settings in the earlier GPOs if there are conflicts. ... So if you said "some machines don't have full access to the network at startup" the GPO's seems not to apply correct. ... in the right window "Group policy Inheritance tab", ... The startup script is applied to the computer, ...
    (microsoft.public.windows.group_policy)
  • Re: Deploy office 2003 to XP workstations
    ... I enabled the policy GPO using GPMC, I'm able to see the setting. ... The network driver starts to late. ... you can set "Run login scripts synchronously". ...
    (microsoft.public.windows.group_policy)
  • Re: EventID 1054 from Userenv for startup script
    ... This order means that the local GPO is processed first, ... So if you said "some machines don't have full access to the network at startup" ... in the right window "Group policy Inheritance tab", ...
    (microsoft.public.windows.group_policy)
  • Re: Please read
    ... >network interact with one of our machines on the internal ... establish a VPN to somebody else's network. ... that would become a policy monitoring and enforcement issue. ... of such policy would be a large security issue in itself. ...
    (microsoft.public.win2000.security)