Re: Internet through VPN



Well why would the users want to change the option?

Its still going to be much faster for them to access the internet locally.

I think this is a training thing more than a technical requirement. You wont be able to do anything on the SBS server, as you need your VPN Clients to connect to it.

Set the option and monitor their use. If needsbe take disciplinary measures. But a technical solution to this will most probably be overkill

Regards,

Matt

"Thomas Raasch" <nospam@xxxxxxxxxx> wrote in message news:err6Kwg$IHA.1224@xxxxxxxxxxxxxxxxxxxxxxx
Hi Matt,

thanks for your reply,



"Matabra" <Matabra@xxxxxxxxxxxxxxxxxxxx> schrieb im Newsbeitrag news:eZimnQg$IHA.4032@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

Do you want your clients to be able to access the internet at the same time as they are connected through the VPN?

yes, it would be very nice
some clients connect to the VPN and then stay connected for hours... it would be bad when the internet won't work in this time
However, as a last possibility this would be an option for me
before they use the SBS site internet it's better they can't use no internet at all
what options do i have to set to disable all the internet?


Is there any specific reason you dont want them using the internet connection at the SBS site?

on one hand it's a bandwith-problem - e.g. when 3 clients try to get windows-updates through the vpn and at the same time 2 other clients make some downloads and so on and so on...
The internet connection at the SBS site is like 16 MBit download and only 1 MBit upload. This is already a bottleneck - even when no client do some downloads

on the other hand there are some "law-problems" - e.g. some vpn-client-users do illegal things like sharing copyrighted music (edonkey or torrent) or they download some illegal pornographic stuff or they post some anti-semitic in official forums or something like this
if 1 week later the police knocks on my door i will be the one who has to explain and to evidence


One way you could do it , (depending on your external firewall at the SBS site) would be to block traffic coming from the VPN clients,

till now there is no firewall on the SBS site except the builtin-one in the router. This router-firewall can not be configured... you can only activate or deactivate it.
Maybe i can use a software-firewall on the sbs-machine? Do you have any suggestions?


Otherwise , send out a new VPN Config file with the "use remote gateway" unchecked and they will use their own gateway.

this would be possible but maybe some users have a little knowledge on networking and can handle google - they would easiely find this option and set it back to its default...
So the only real way is to block internet through vpn, am i right?


Regards,
Thomas

.



Relevant Pages

  • Re: Internet through VPN
    ... Do you want your clients to be able to access the internet at the same time as they are connected through the VPN? ... The Router is the Gateway for that XP-Client ...
    (microsoft.public.windows.server.sbs)
  • Re: Offsite DNS question
    ... > I assumed the clients are using VPNs. ... > logging on across the internet without a VPN. ... in between the clients and the internal network, ...
    (microsoft.public.win2000.active_directory)
  • Re: RRAS Issue -Dual NICs
    ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... The server also provides dial-up access through modems so stranded clients ... They also get assigned to that 10.x network. ...
    (microsoft.public.windows.server.networking)
  • Re: No web browsing on VPN client
    ... It appeared a rule was blocking VPN clients in ISA 2004, ... blockage was no longer being recorded, however still not internet. ... Log type: Firewall service ...
    (microsoft.public.isa)
  • Re: ISA Server Problems, please help
    ... > clients are unaffected, is it secureNAT clients which are affected? ... then checked Send the original host header to the publishing server instead ... > provided unrestricted internet access. ...
    (microsoft.public.windows.server.sbs)