Networking Forums

Networking Forums > Computer Networking > Windows Networking > Connected through VPN,but..

Reply
Thread Tools Display Modes

Connected through VPN,but..

 
 
=?Utf-8?B?cmFscGggbWFjZG91Z2xhcw==?=
Guest
Posts: n/a

 
      10-06-2004, 08:27 PM
I configured my VPN server on Server 2003. I finally got the access folder
permission going as well. Now my own problem is that everyone who connects to
my vpn server will use my internet connection to browse the internet. I am
connected to the internet via a D-Link 624+ router. This router give my LAN
the internet. is there a way to deny internet access to the dialing in VPN
clients so that they use their own internet connection?

thx

ralph macdouglas
 
Reply With Quote
 
 
 
 
Steven L Umbach
Guest
Posts: n/a

 
      10-06-2004, 11:45 PM
I have never tried to do what you want but what I would try is to see if you
can configure your router to deny internet access to those IP addresses that
your VPN server hands out to VPN clients. It may be easier to configure a
static IP address pool on the VPN server and then deny those addresses if
you currently use DHCP. Another thing that may work is to use Remote Access
Policies where you can configure input filters where you could add entries
to block traffic with destination ports of 80/443/20/21/25/110/119 tcp and
such. You can configure Remote Access Policies in the Remote Access
Management Console - server name/Remote Access Policies. Open the policy and
select edit profile/IP to access from client IP packet filters. --- Steve


"ralph macdouglas" <(E-Mail Removed)> wrote in
message news:E6CB8612-A459-4DCA-95E0-(E-Mail Removed)...
>I configured my VPN server on Server 2003. I finally got the access folder
> permission going as well. Now my own problem is that everyone who connects
> to
> my vpn server will use my internet connection to browse the internet. I am
> connected to the internet via a D-Link 624+ router. This router give my
> LAN
> the internet. is there a way to deny internet access to the dialing in VPN
> clients so that they use their own internet connection?
>
> thx
>
> ralph macdouglas



 
Reply With Quote
 
Bill Grant
Guest
Posts: n/a

 
      10-07-2004, 02:03 AM
Note that if you deny clients access to the Internet through your server
they will lose Internet access altogether while the VPN is up, unless they
modify their connection properties.

When a client makes a remote access connection (RAS or VPN), the current
default route is disabled (by increasing its metric) and a new default route
established to the remote server. That is why all their Internet traffic is
coming to you.

To change this, the connection properties of the client must be changed
by clearing the "use default gateway.." box in the advanced TCP/IP settings
for the connection. The default route to the Internet then stays alive, and
only a subnet route is configured to the server.

"Steven L Umbach" <(E-Mail Removed)> wrote in message
news:e59wI6$(E-Mail Removed)...
>I have never tried to do what you want but what I would try is to see if
>you can configure your router to deny internet access to those IP addresses
>that your VPN server hands out to VPN clients. It may be easier to
>configure a static IP address pool on the VPN server and then deny those
>addresses if you currently use DHCP. Another thing that may work is to use
>Remote Access Policies where you can configure input filters where you
>could add entries to block traffic with destination ports of
>80/443/20/21/25/110/119 tcp and such. You can configure Remote Access
>Policies in the Remote Access Management Console - server name/Remote
>Access Policies. Open the policy and select edit profile/IP to access from
>client IP packet filters. --- Steve
>
>
> "ralph macdouglas" <(E-Mail Removed)> wrote in
> message news:E6CB8612-A459-4DCA-95E0-(E-Mail Removed)...
>>I configured my VPN server on Server 2003. I finally got the access folder
>> permission going as well. Now my own problem is that everyone who
>> connects to
>> my vpn server will use my internet connection to browse the internet. I
>> am
>> connected to the internet via a D-Link 624+ router. This router give my
>> LAN
>> the internet. is there a way to deny internet access to the dialing in
>> VPN
>> clients so that they use their own internet connection?
>>
>> thx
>>
>> ralph macdouglas

>
>



 
Reply With Quote
 
=?Utf-8?B?cmFscGggbWFjZG91Z2xhcw==?=
Guest
Posts: n/a

 
      10-07-2004, 12:17 PM
Yesterday everything was working fine, but today thats a different story!
Yesterday when i opend the comand prompt windows and typed "ipconfig" i saw 2
network addresses. The first one was RAS something which gave me an ip and
the second one I saw my NIC with its IP address. Now the ras is gone when i
type in ipconfig. This and the working vpn is gone, and i dont know why, i
didnt do i promise People still can try to dial in but the username and
password get rejected. Does anyone know how to get it back? Thx for the hellp
so far, greatly appreciated

Ralph
 
Reply With Quote
 
Bill Grant
Guest
Posts: n/a

 
      10-08-2004, 01:53 AM
The internal interface only gets an IP after the first client connects.
When you fix the security problem it will reappear when a client connects.

"ralph macdouglas" <(E-Mail Removed)> wrote in
message news:6508E13E-F815-4846-9773-(E-Mail Removed)...
> Yesterday everything was working fine, but today thats a different story!
> Yesterday when i opend the comand prompt windows and typed "ipconfig" i
> saw 2
> network addresses. The first one was RAS something which gave me an ip and
> the second one I saw my NIC with its IP address. Now the ras is gone when
> i
> type in ipconfig. This and the working vpn is gone, and i dont know why, i
> didnt do i promise People still can try to dial in but the username and
> password get rejected. Does anyone know how to get it back? Thx for the
> hellp
> so far, greatly appreciated
>
> Ralph



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Shows As Not Connected But Is Connected Dell Boy Wireless Networks 9 05-18-2010 07:34 AM
Connection between a lan-connected pc and a wireless connected Ciaccihome Wireless Networks 1 08-17-2006 11:00 AM
Connected disconnect, disconnected Connected Jefferis NoSpamme Wireless Internet 2 07-28-2005 06:04 PM
problem: wireless MN-500 connected, but not connected Andrew Smith Broadband Hardware 2 08-21-2004 12:28 AM
problem: connected, but not connected to a wireless network Andrew Smith Wireless Networks 0 08-20-2004 07:51 PM



1 2 3 4 5 6 7 8 9 10 11