Networking Forums

Networking Forums > Computer Networking > Windows Networking > Domain login with VPN

Reply
Thread Tools Display Modes

Domain login with VPN

 
 
jacksors
Guest
Posts: n/a

 
      10-11-2006, 04:43 PM
We recently setup a Windows Server 2003 as a VPN server using radius
authentication with RSA security. We only have a few users right now that
connect and use the VPN however we have plans to expand and give access to
many of our remote users. The current users are all corporate office users
whose pc's are a member of the domain. When they go home, they login using
cached credentials and then establish the VPN connection and are able to
access email and mapped drives and all of that stuff.

With the current corporate users, do their cached credentials carry all the
ACL's associated with their account? So they should not be able to access
anything that they couldn't from the corporate LAN?

The remote users we will be adding are not a member of the domain. Their
laptops login using a local administrative account. How can I get these users
to login to the domain after establishing the VPN connection? They are all
using the Microsoft VPN client on their XP SP2 laptops. Ideally what I would
like is that after they establish the VPN connection, a script or some other
program should automatically run to prompt for domain credentials and run a
login script to map drives for those users.

Since they are not members of the domain, would they be able to access
drives or other internal resources with out logging into the domain?
 
Reply With Quote
 
 
 
 
Frankster
Guest
Posts: n/a

 
      10-11-2006, 04:56 PM
Are your home users logging onto the domain or simply onto the VPN server?

Dialup VPN connection | Properties | Options | Ticbox "Windows Domain
Logon". This will allow them to specify the domain. They will need a domain
account.

-Frank

"jacksors" <(E-Mail Removed)> wrote in message
news:CE94A47B-D72A-42C8-8816-(E-Mail Removed)...
> We recently setup a Windows Server 2003 as a VPN server using radius
> authentication with RSA security. We only have a few users right now that
> connect and use the VPN however we have plans to expand and give access to
> many of our remote users. The current users are all corporate office users
> whose pc's are a member of the domain. When they go home, they login using
> cached credentials and then establish the VPN connection and are able to
> access email and mapped drives and all of that stuff.
>
> With the current corporate users, do their cached credentials carry all
> the
> ACL's associated with their account? So they should not be able to access
> anything that they couldn't from the corporate LAN?
>
> The remote users we will be adding are not a member of the domain. Their
> laptops login using a local administrative account. How can I get these
> users
> to login to the domain after establishing the VPN connection? They are all
> using the Microsoft VPN client on their XP SP2 laptops. Ideally what I
> would
> like is that after they establish the VPN connection, a script or some
> other
> program should automatically run to prompt for domain credentials and run
> a
> login script to map drives for those users.
>
> Since they are not members of the domain, would they be able to access
> drives or other internal resources with out logging into the domain?



 
Reply With Quote
 
jacksors
Guest
Posts: n/a

 
      10-11-2006, 06:11 PM
Their home(remote) laptop is not a member of the domain. Right now they are
just establishing a VPN connection, I would like them to be prompted to login
to the domain after the VPN connection gets establish so they don't have to
provide their credentials every time they access a file share. Also, once
they authenticate to the domain, I would like a login script to run.

I checked that box as suggested but was not prompted for a domain login
after the VPN connection was established. Each client needs to have th RSA
security protocol loaded in order to use the RSA EAP authentication method
for the VPN. This software modifies the default VPN interface slightly. I'm
wondering if this software is preventing a domain prompt from appearing?

Any other thoughts on how to accomplish a single-sign on domain prompt that
executes a login script?

"Frankster" wrote:

> Are your home users logging onto the domain or simply onto the VPN server?
>
> Dialup VPN connection | Properties | Options | Ticbox "Windows Domain
> Logon". This will allow them to specify the domain. They will need a domain
> account.
>
> -Frank
>
> "jacksors" <(E-Mail Removed)> wrote in message
> news:CE94A47B-D72A-42C8-8816-(E-Mail Removed)...
> > We recently setup a Windows Server 2003 as a VPN server using radius
> > authentication with RSA security. We only have a few users right now that
> > connect and use the VPN however we have plans to expand and give access to
> > many of our remote users. The current users are all corporate office users
> > whose pc's are a member of the domain. When they go home, they login using
> > cached credentials and then establish the VPN connection and are able to
> > access email and mapped drives and all of that stuff.
> >
> > With the current corporate users, do their cached credentials carry all
> > the
> > ACL's associated with their account? So they should not be able to access
> > anything that they couldn't from the corporate LAN?
> >
> > The remote users we will be adding are not a member of the domain. Their
> > laptops login using a local administrative account. How can I get these
> > users
> > to login to the domain after establishing the VPN connection? They are all
> > using the Microsoft VPN client on their XP SP2 laptops. Ideally what I
> > would
> > like is that after they establish the VPN connection, a script or some
> > other
> > program should automatically run to prompt for domain credentials and run
> > a
> > login script to map drives for those users.
> >
> > Since they are not members of the domain, would they be able to access
> > drives or other internal resources with out logging into the domain?

>
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Login to domain via vpn Daniel Windows Networking 0 03-26-2006 03:37 PM
Domain Login over VPN. Don Doerr Windows Networking 4 10-05-2005 02:07 AM
Sometimes users can't login after changing password on domain at first login edg Windows Networking 0 11-11-2004 11:30 PM
Can't login to domain Graeme Wireless Networks 0 10-19-2004 03:01 PM
domain/workstation login Marty Windows Networking 1 09-10-2004 12:10 AM



1 2 3 4 5 6 7 8 9 10 11