Solved

VPN users authenticate as guests for network resources.

Posted on 2004-08-12
3
224 Views
Last Modified: 2010-04-19
Hi,
I am running windows 2003 server and have VPN setup on a machine, Users can access VPN, connect to our outbound internet and access our internal resources, however they are authenticated as Guests and thus have limited access to network resources.  What is happening here.  

This is the second time this problem has occurred.  
Once on windows 2000
and another time on windows XP

Both PC's do not have a (login)password set.

I want to allow these individuals to connect without requireing them to change thier username/password to match our internal network.
0
Comment
Question by:JakeWSYSA
  • 2
3 Comments
 
LVL 1

Expert Comment

by:012Uvongo
ID: 11791032

Hey mate

Your VPN server is it a standalone server? How do users obtain an IP address through the RRAS server or through the DHCP server?

Have you tried IAS?

Internet Authentication Service (IAS) in Microsoft® Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise Edition; and Windows Server 2003, Datacenter Edition is the Microsoft implementation of a Remote Authentication Dial-in User Service (RADIUS) server and proxy. As a RADIUS server, IAS performs centralized connection authentication, authorization, and accounting for many types of network access including wireless, authenticating switch, and remote access dial-up and virtual private network (VPN) connections. As a RADIUS proxy, IAS forwards authentication and accounting messages to other RADIUS servers

You can configure IAS in Windows Server 2003, Standard Edition, with a maximum of 50 RADIUS clients and a maximum of 2 remote RADIUS server groups. You can define a RADIUS client using a fully qualified domain name or an IP address, but you cannot define groups of RADIUS clients by specifying an IP address range. If the fully qualified domain name of a RADIUS client resolves to multiple IP addresses, the IAS server uses the first IP address returned in the DNS query. With IAS in Windows Server 2003, Enterprise Edition, and Windows Server 2003, Datacenter Edition, you can configure an unlimited number of RADIUS clients and remote RADIUS server groups. In addition, you can configure RADIUS clients by specifying an IP address range.

0
 
LVL 1

Author Comment

by:JakeWSYSA
ID: 11794455
So, in my senario. I have volunteer administers that need access to corporate resources.  They dial-in using vpn and are authenticated.  The Users that have identical windows username/passwords set can access resources, however the users that have no username/passwords matching thier coroporate passwords get logged in as guest.  I have IAS already installed and one rule is listed and i believe this could be my problem.

"Use Windows authentication for all users"

In the case of the remote users I would rather use thier VPN username/password for local resources.  I tried adding a rule but it didn't work well, please help.

0
 
LVL 1

Accepted Solution

by:
012Uvongo earned 50 total points
ID: 11818118
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

822 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question