Networking Forums

Networking Forums > Computer Networking > Windows Networking > IAS Policy

Reply
 
 
ultraman
Guest
Posts: n/a

 
      06-27-2006, 02:19 AM
Hi,

I've created 2 rules in Remote Access Policies, one is Grant Remote Access
Permission and the other is Denied Remote Access Permission.

So far all the users is able to connect the PPTP vpn but recently I tried
to block certain user to connect so I have created a Local Group call Denied
Access and created a policy call Denied Access Policy & add the Denied Access
group to the condition list. This policy is set to Denied Remote Access
Permission(The order is set to 1).

Then I tried to add myself to this Denied Access group but I still able to
get connected. I checked the log file and it show that I'm using the Denied
Access Policy. (FYI, my account under AD is granted Allow Access in Dial In
tab).

May I know why the policy is not restricted me to connect the vpn(RAS)?

Thanks.
 
Reply With Quote
 
 
 
 
ultraman
Guest
Posts: n/a

 
      06-27-2006, 03:12 AM
I've found out the problem for the policy: the AD dial-in properties of the
user or computer account overrides the remote access policy.

Btw, is there anyway to deny the user remote access other than change the
permission to Denied Access in AD?

Thanks.


"ultraman" wrote:

> Hi,
>
> I've created 2 rules in Remote Access Policies, one is Grant Remote Access
> Permission and the other is Denied Remote Access Permission.
>
> So far all the users is able to connect the PPTP vpn but recently I tried
> to block certain user to connect so I have created a Local Group call Denied
> Access and created a policy call Denied Access Policy & add the Denied Access
> group to the condition list. This policy is set to Denied Remote Access
> Permission(The order is set to 1).
>
> Then I tried to add myself to this Denied Access group but I still able to
> get connected. I checked the log file and it show that I'm using the Denied
> Access Policy. (FYI, my account under AD is granted Allow Access in Dial In
> tab).
>
> May I know why the policy is not restricted me to connect the vpn(RAS)?
>
> Thanks.

 
Reply With Quote
 
Bill Grant
Guest
Posts: n/a

 
      06-27-2006, 10:12 AM
The usual method is to make membership of a particular group a condition
for access in the policy. Users who are not in that group will be denied
access.

ultraman wrote:
> I've found out the problem for the policy: the AD dial-in properties
> of the user or computer account overrides the remote access policy.
>
> Btw, is there anyway to deny the user remote access other than change
> the permission to Denied Access in AD?
>
> Thanks.
>
>
> "ultraman" wrote:
>
>> Hi,
>>
>> I've created 2 rules in Remote Access Policies, one is Grant
>> Remote Access Permission and the other is Denied Remote Access
>> Permission.
>>
>> So far all the users is able to connect the PPTP vpn but recently
>> I tried to block certain user to connect so I have created a Local
>> Group call Denied Access and created a policy call Denied Access
>> Policy & add the Denied Access group to the condition list. This
>> policy is set to Denied Remote Access Permission(The order is set to
>> 1).
>>
>> Then I tried to add myself to this Denied Access group but I still
>> able to get connected. I checked the log file and it show that I'm
>> using the Denied Access Policy. (FYI, my account under AD is granted
>> Allow Access in Dial In tab).
>>
>> May I know why the policy is not restricted me to connect the
>> vpn(RAS)?
>>
>> Thanks.



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
policy Microsoft Windows Networking 1 11-08-2006 01:37 PM
Slashdots new policy Michael Hearne Linux Networking 1 02-08-2006 02:15 PM
Cant locate wireless network policy in group policy Tom Windows Networking 0 05-11-2005 01:28 PM
Group Policy BA Home Networking 4 06-15-2004 12:16 PM
policy Hing Windows Networking 0 08-19-2003 12:01 PM



1 2 3 4 5 6 7 8 9 10 11