Networking Forums

Networking Forums > Computer Networking > Windows Networking > Create user that only has access to VPN?

Reply
Thread Tools Display Modes

Create user that only has access to VPN?

 
 
CoolHandJoe
Guest
Posts: n/a

 
      12-30-2006, 03:32 AM
Hi all

Recently a client of mine asked to setup some users to have access to
the network via VPN but not to anything else. It turns out there is
another company in the office and they have resources that are not
managed by the Windows 2003 server domain. They want to give them
access but restrict access to all domain resources. I know that for
the most part shares are controlled by an ACL but it is possible to
have shares available to the everyone group and they would like that to
be restricted as well. Is it possible to restrict that without having
to go to every share and explicitly denying the other group access to
everything?

Joe

 
Reply With Quote
 
 
 
 
Bill Grant
Guest
Posts: n/a

 
      12-31-2006, 12:22 AM
A VPN connection gives you an IP connection to the network. Remote access
policies are only concerned with whether a user has the right to connect.
What files the remote user can access is a completely different issue.

"CoolHandJoe" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed) ups.com...
> Hi all
>
> Recently a client of mine asked to setup some users to have access to
> the network via VPN but not to anything else. It turns out there is
> another company in the office and they have resources that are not
> managed by the Windows 2003 server domain. They want to give them
> access but restrict access to all domain resources. I know that for
> the most part shares are controlled by an ACL but it is possible to
> have shares available to the everyone group and they would like that to
> be restricted as well. Is it possible to restrict that without having
> to go to every share and explicitly denying the other group access to
> everything?
>
> Joe
>


 
Reply With Quote
 
CoolHandJoe
Guest
Posts: n/a

 
      12-31-2006, 01:43 AM
Thanks for the reply Bill.

That's true, however, to give these people VPN access I need to create
them on the server as a user and at a minimum they can use their user
name and password to attempt to access shares on the network. Also, by
default they will be given access to anything available to the
everyone, authenticated users, and network groups. Not so sure about
the network group. The problem is that there are many shares created
already and I don't want to have to go to each share on the server and
remove those groups because that might actually be a problem for some
of the shares like the public share. I imagine that I could place all
the other users and put them in a group (say the other users group)
then somehow deny access to everything except dial in. The problem is
that I don't know of any policy that will allow me to do that.
Anyone have any suggestions?

Joe


Bill Grant wrote:
> A VPN connection gives you an IP connection to the network. Remote access
> policies are only concerned with whether a user has the right to connect.
> What files the remote user can access is a completely different issue.
>
> "CoolHandJoe" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed) ups.com...
> > Hi all
> >
> > Recently a client of mine asked to setup some users to have access to
> > the network via VPN but not to anything else. It turns out there is
> > another company in the office and they have resources that are not
> > managed by the Windows 2003 server domain. They want to give them
> > access but restrict access to all domain resources. I know that for
> > the most part shares are controlled by an ACL but it is possible to
> > have shares available to the everyone group and they would like that to
> > be restricted as well. Is it possible to restrict that without having
> > to go to every share and explicitly denying the other group access to
> > everything?
> >
> > Joe
> >


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
User is unable to access their user directory Nauip Windows Networking 1 04-08-2008 02:32 AM
How to create an SSH/telnet user with read-only permissions ? Peter Ballmer Linux Networking 0 10-20-2007 09:58 AM
plz help to create a windows server 2003 domain member user ads Windows Networking 1 04-07-2007 02:56 PM
standard xp user cant create file on C root Scott Windows Networking 1 02-15-2007 04:48 PM
Cannot create folder access denied =?Utf-8?B?RGF2aWRN?= Windows Networking 1 12-16-2003 02:48 AM



1 2 3 4 5 6 7 8 9 10 11