Advertisement

03.28.2008 at 05:38PM PDT, ID: 23278871 | Points: 500
[x]
Attachment Details
Permissions to create or use a VPN connection
We have a domain that allows remote access and VPN connections from the outside. Workstations on our domain are not allowed to create or use a VPN. Outside computers have no problem creating a VPN. We now have a laptop that has joined the domain and must travel and be able to remote in through a VPN. The laptop will only allow the laptop local or domain admin account to create or use the VPN. All other user accounts on the laptop are not allowed to use the connection or create one, even if added to the local machines admin group. The domain user of the laptop has already been added to the "Network Configuration Operator" group as well but has had no effect.
A policy on the domain must be preventing this but I can't be sure which one and need to avoid opening a gaping hole in our security. Can anybody help with this?
Start your free trial to view this solution
Question Stats
Zone: Software
Question Asked By: Spigniff
Question Asked On: 03.28.2008
Participating Experts: 1
Points: 500
Views: 0
Translate:
Loading Advertisement...
03.28.2008 at 05:46PM PDT, ID: 21234991

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.28.2008 at 07:25PM PDT, ID: 21235214

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.28.2008 at 08:01PM PDT, ID: 21235356

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.28.2008 at 08:40PM PDT, ID: 21235441

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.29.2008 at 08:19AM PDT, ID: 21236842

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Handhelds / PDAs
  • Displays / Monitors
  • Components
  • Networking Hardware
  • Peripherals
  • Laptops/Notebooks
  • Storage
  • Servers
  • Desktops
  • New Users
  • Misc
  • Apple
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMWare
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMWare
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Community Advisor
  • Lounge
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • Community Advisor
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
03.28.2008 at 05:46PM PDT, ID: 21234991
 
03.28.2008 at 07:25PM PDT, ID: 21235214

Rank: Genius

Not sure I fully understand the question. When the VPN connection is created on the workstation/laptop, you are given the option to allow anyone or just the creator to use the VPN.

As far as the domain is concerned, access is controlled by user rather than by device. You can control access by using the Access allowed or denied option on the users dial-up tap of their profile. If you would like more centralized control you can create a group of allowed users and control it with a policy in the RRAS console.
 
03.28.2008 at 08:01PM PDT, ID: 21235356
The only accounts allowed to create the VPN connection on the laptop (or any other workstation on the domain) are the domain admin accounts or the local machine administrator account. The connection is given the setting of "allow anybody to connect that uses this computer". When any account logs in (local or domain) that is not an administrator the launching of the connection is blocked and an "access denied" message appears with a note that it generally means you are logged in as a guest (which is not the case).  
 
03.28.2008 at 08:40PM PDT, ID: 21235441
Currently, remote access into our network is controlled by the setting "control access through remote access policy" on the user's dial-up tab. We have policies in place for gorup membership, etc... in RRAS. I toggled a user setting on the dial-up tab to "Allow" instead of through remote policy and the same blocking occurs. The error message states you don't have "permission" to use this connection but I still believe it's actually a domain policy pertaining to "rites". As I stated earlier, a machine at home (not joined to the domain) can create and use a VPN connection to our network if the proper login is used. This is why I think it is actually a default domain policy passed down to the machine when it joins the domain. Adding the user to the admin group of the local machine fails to allow the use of the connection but a login "with" the administrator account of the local machine allows it. That eliminates "permissions" and points to "rites" in my mind.
 
03.29.2008 at 08:19AM PDT, ID: 21236842

Rank: Genius

I am not sure what the actual question is?

>>"The only accounts allowed to create the VPN connection on the laptop "
One of the disadvantages of the Windows VPN is anybody on an unknown computer can create the VPN connection. The only thing blocking them from access is an acceptable user name and password. If they know that, they can access, unless you can assign restrictions such as the IP from which they connect.

For additional security you are better using an IPSec VPN solution that requires pass phrases or better still certificates, in order to connect. Also with most you can control installation of the VPN client.
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628