Re: restrict folder access while VPN is established



Hi

Thanks a lot Steve. Sounds good. Since my Remote users has RDP over HTTP for
Outlook there isn't really a need for remote logging with the same user
account unless the server gets confused those two credentials used in the
same time, right?

How ever. If they do login by PPTP over IPSec VPN with a different user name
what do you suggest for NT rights in the server? Deny rights for "VPN Group"
in every shared data folder except that shared folder they need the access?
Should I deny any system's shared folder?

Rgs,

Juha

"Steve Foster [SBS MVP]" wrote:

Juha wrote:

Hi

SBS 2003 R2. My customers policy is that VPN users (3rd party IPSec) must
only see one special folder (and subfolders) via VPN. At Office they can
see
other shares. Unfortunately now they can see same shares via VPN as
locally.

How to implement this, Remote Policy perhaps?

Use different credentials for VPN. File and Share security is not based on
user location, only user account.

--
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.

.



Relevant Pages

  • Re: Accessing files from remote locations.
    ... shared folder on the server with her laptop. ... We do not have a VPN appliance, but we do have a server with 2 NICs. ... Remote Web Workspace is currently running and the workers who have desktops at the office can login in remotely and access shared folders. ...
    (microsoft.public.windows.server.sbs)
  • Re: Share files remotely
    ... Steve O'Hara-Smith wrote: ... remote user's securely. ... So far the VPN is what I have gathered also. ... I'll look into the openvpn. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Remote Access and ISA Server in SBS 2003?
    ... I am glad to hear the Remote Access Wizard is working fine now. ... there is no difference in VPN between SBS 4.5 and SBS ... Error Message: VPN Connection Error 800: Unable to Establish Connection ... the external NIC of the SBS Server. ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN Problem with a domain account versus local computer account
    ... logon domain remotely. ... allow VPN client access, and there is a client computer that is configured ... Enable remote access on domain user accounts ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS VPN setup?
    ... Do you really think it is easier to set up a RWW in SBS 2003 R2 Standard as you claim? ... Note that almost all routers are not designed to allow more than one PPTP VPN from the same remote IP address, (the PPTP protocol does allow for the possibility of multiple tunnels, but they must share a control channel, which means it can't be done from separate remote computers behind one NAT router without fairly exotic packet handling) so if you need multiple users at one site you really need site-to-site VPN. ...
    (microsoft.public.windows.server.sbs)