Chad
Mon Sep 29 16:30:53 CDT 2003
Hi Nathan -
Tom covers the subject pretty well:
http://www.isaserver.org/tutorials/VPN_Client_Security_Issues.html
--
Chad A Gross - SBS Rocks!
Lerman's Law of Technology: Any technical problem can be overcome
given enough time and money. Corollary: You are never given enough
time or money.
NetNathan wrote:
> On the remote pc which is establishing vpn to the server, what is the
> risk of un-checking "Use Default Gateway"?
> Can this be better explained, beyond "security risk"?
> Does it help if the remote pc is also behind a router and firewall?
> -nn
>
>
> "Chad A Gross" <chad.gross@laytonflower.nospam.com> wrote in message
> news:ecmxNSjhDHA.1800@TK2MSFTNGP09.phx.gbl...
>> Hi Scott -
>>
>> If you are utilizing ISA at your location, then the security risk
>> associated with unchecking 'Use default gateway' is minimal, since
>> you're behind ISA. Changing this setting becomes much more of a
>> security issue when we're talking about roaming / home users where
>> we often do not have control over the remote PC.
>>
>> --
>> Chad A Gross - SBS Rocks!
>>
>> Lerman's Law of Technology: Any technical problem can be overcome
>> given enough time and money. Corollary: You are never given enough
>> time or money.
>>
>>
>>
>> jimbehning@mindspring.com wrote:
>>> Do a google search in this newsgroup for default gateway. There are
>>> security issues related to changing the checkbox. Default gateway is
>>> found in the vpn connection properties. Remoter computers should be
>>> up to date on all patches and AV definitons. Well they should be
>>> bedfore you let them vpn in anyway. Some administrators insist that
>>> the remote user computer have some sort of firewall installed
>>> before they can
>>> vpn.
>>>
>>> "Scott" <scott@cadyco.com> wrote:
>>>
>>>> I have setup and configured a VPN to an offsite server
>>>> which works fine. However, when I connect the VPN, I lose
>>>> internet access. (Am running SBS2000 here). I saw a post
>>>> a while back about a setting to change to allow internet
>>>> access while connected to the VPN but I can't find it
>>>> again. As I recall, it was very simple (couple of clicks)
>>>> but damned if I can remember what it was!
>>>>
>>>> Thanks!
>>>>
>>>> Scott
>>>
>>> Jim B. SBS MVP