Access to office network through a "VPN PC" connected to a public wireless network

H

Harald

Hi


My WinXP-PC SP3 PC (all windows updates installed) was connected to a
wireless network. At the same time a VPN connection to my office network was
open. Then I connected a Vista SP1 PC to the same wireless network. On the
vista PC all PCs on my office network was listed. For me this looks like a
real security problem. (If I am connected to a public network all other PCs
connected have access to my office network?)



Questions:
1: Is that a know security problem?
2: Available patches / Policy setting to avoid this?

Thanks in advance


Harald



__________ Information from ESET NOD32 Antivirus, version of virus signature database 3948 (20090319) __________

The message was checked by ESET NOD32 Antivirus.

http://www.eset.com
 
H

Harald

Hi

On
http://www.directionsonmicrosoft.com/sample/DOMIS/update/2006/09sep/0906wnrfe.htm I
found the information below which decribes what happend to me:
"Windows XP, for example, can be configured so that when a user initiates a
VPN connection to a private intranet across the Internet, the user's
computer enables traffic to be forwarded between the Internet and the VPN
connection, possibly compromising corporate security. Windows Vista and
Longhorn Server, in contrast, provide separate sets of IP routing tables for
each set of network adapters and user sessions, eliminating the risk that a
user can manually create a routing table entry that allows unwanted
forwarding."

Do you know if it is possible to patch / disable this functionality on a PC
running XP SP3?

Harald


Harald said:
Hi


My WinXP-PC SP3 PC (all windows updates installed) was connected to a
wireless network. At the same time a VPN connection to my office network
was open. Then I connected a Vista SP1 PC to the same wireless network. On
the vista PC all PCs on my office network was listed. For me this looks
like a real security problem. (If I am connected to a public network all
other PCs connected have access to my office network?)



Questions:
1: Is that a know security problem?
2: Available patches / Policy setting to avoid this?

Thanks in advance


Harald



__________ Information from ESET NOD32 Antivirus, version of virus
signature database 3948 (20090319) __________

The message was checked by ESET NOD32 Antivirus.

http://www.eset.com



__________ Information from ESET NOD32 Antivirus, version of virus signature database 3948 (20090319) __________

The message was checked by ESET NOD32 Antivirus.

http://www.eset.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top