RE: VPN 3000 client

From: Raymond Jett (rajett@xxxxxxxxx)
Date: Wed Jul 31 2002 - 15:01:19 GMT-3


   
Look up the concept of "Split Tunneling" in the VPN Concentrator Docs...

Enable that to solve your issue...

HOWEVER!

This opens security hole if you pc has been compromised by hackers (if
someone has has installed back orifice or other utilities)... they will have
access to your internal network.

NOW...

You have to set this up on the concentrator as these settings are "pushed"
to the client when they connect. This helps to enforce your security
policies from a central location.

Raymond

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com]On Behalf Of
Peter Wodle
Sent: Wednesday, July 31, 2002 12:30 PM
To: security@groupstudy.com; ccielab@groupstudy.com
Subject: Re: VPN 3000 client

OK, I can logon to NT domain via Radius with Cisco VPN client. The issue now
is when VPN client is firedup, can't browse Internet anyloger. Any ideas how
the Internet traffic can be directed to stay outside VPN tunnel & go to the
Internet rather than the tunnel?

>From: "Peter Wodle" <Peter_Wodle@hotmail.com>
>To: <security@groupstudy.com>
>Subject: VPN 3000 client
>Date: Fri, 26 Jul 2002 18:28:03 +0100
>
>Can anyone suggest the best (most secure etc) way to connect to NT 4 domain
>network from the Internet via Cisco VPN 3005? Should I use the Cisco VPN
>client? What authentication method is best e.g. RADIUS on NT 4 server
>domain etc?
>



This archive was generated by hypermail 2.1.4 : Sat Sep 07 2002 - 19:36:50 GMT-3