Question On Internet Access While Logged In As VPN CLient

J

JIMB

Question On Internet Access While Logged In As VPN CLient

We have MSESKSB SERVER w\Firewall.

My question is, can the VPN (outside!) (WAN,) client's
while logged in to the Server & going through our
Firewall, be able to access the internet through another
port on the Firewall or from their own systems without
jeopardizing & opening up the virtual & private connection
to the outside internet world?

I know there is a switch we can set on the VPN advance
TCP/IP properties to allow this, However, I also know that
this "opens" & defeats the reason for the Virtural &
Private Conection.

Can this be done safely? If so, how?

As Always, I Look Forward In Hearing Your Advise Jim B.


..
 
S

Steven Umbach

That is called split tunnel vulnerability. It is theoretically possible for an
attacker to use it to compromise the vpn network, but proper configuration can
greatly reduce the risk which would include a personal firewall on the users
computer assuming they do not disable it. Of course any worm/trojan a user gets
on their computer could infect a network via a vpn also as could a stolen laptop
if the user has a weak password or uses the save password feature for their vpn
connectiod which are probably lot more likely risks. See the article below on
the subject. --- Steve

http://www.nwfusion.com/news/2003/0224splittunnels.html?nl
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top