Networking Forums

Networking Forums > Computer Networking > Windows Networking > VPN access policy

Reply
Thread Tools Display Modes

VPN access policy

 
 
rickpier
Guest
Posts: n/a

 
      07-29-2005, 10:21 AM
I want to authorise users to connect to our VPN only if they are using our
computers.
I create two groups one with the users and one with the computer.

How can I write these conditions in the remote access policies? (I don't
know how to write AND operator)?

Rickpier


 
Reply With Quote
 
 
 
 
Ewan
Guest
Posts: n/a

 
      07-30-2005, 03:16 PM


"rickpier" wrote:

> I want to authorise users to connect to our VPN only if they are using our
> computers.
> I create two groups one with the users and one with the computer.
>
> How can I write these conditions in the remote access policies? (I don't
> know how to write AND operator)?
>
> Rickpier
>
>
>

this is not my speciality, but.....

if i understand correctly you are trying to specify in the "Policy
COnditions" that access is granted if COMPUTER is a member of
domain\Computers and the USER is a member of domain\Users ?
I dont believe this will work because the "Windows-Groups" attribute only
evaluates the groups the USER is a member of.

I think there are at least three approaches:
take a look at the "Client-Friendly-Name" attribute - i think you can use
this to match .+mydomain (you might need to find a primer on regular
expressions first)
this is not fool proof (if users join their computers to their own
"whoever.dom" domain)

read up on remote access quarantine control -
http://www.microsoft.com/windowsserv...uarantine.mspx
this is not fool proof (technical users will be able to get around this if
you use all the supplied MS sample components)

if you have a certificate infrastructure (or can deploy and maintain one)
then look into using L2TP VPN ports (short overview and links
http://www.microsoft.com/technet/com...uy/cg0101.mspx) - in
this way all client PCs have to have a PC certificate issued by your domain.
This probably is the most secure (assuming it is set up correctly) but will
likely require the most work

ewan

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problems with Remote Access Policy Allie Windows Networking 0 07-27-2007 07:50 PM
IAS/RADIUS Remote access policy leobis Windows Networking 0 12-09-2006 11:55 AM
rras-remote access policy siamac.jk Windows Networking 0 01-05-2006 01:06 PM
The local policy Allow Access to this computer from the network is Carl Windows Networking 0 08-18-2005 01:11 AM
Need a policy popup windows before logon access Clayton Sutton Windows Networking 7 02-02-2005 12:29 AM



1 2 3 4 5 6 7 8 9 10 11