Solved

VPN users authenticate as guests for network resources.

Posted on 2004-08-12
3
217 Views
Last Modified: 2010-04-19
Hi,
I am running windows 2003 server and have VPN setup on a machine, Users can access VPN, connect to our outbound internet and access our internal resources, however they are authenticated as Guests and thus have limited access to network resources.  What is happening here.  

This is the second time this problem has occurred.  
Once on windows 2000
and another time on windows XP

Both PC's do not have a (login)password set.

I want to allow these individuals to connect without requireing them to change thier username/password to match our internal network.
0
Comment
Question by:JakeWSYSA
  • 2
3 Comments
 
LVL 1

Expert Comment

by:012Uvongo
Comment Utility

Hey mate

Your VPN server is it a standalone server? How do users obtain an IP address through the RRAS server or through the DHCP server?

Have you tried IAS?

Internet Authentication Service (IAS) in Microsoft® Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise Edition; and Windows Server 2003, Datacenter Edition is the Microsoft implementation of a Remote Authentication Dial-in User Service (RADIUS) server and proxy. As a RADIUS server, IAS performs centralized connection authentication, authorization, and accounting for many types of network access including wireless, authenticating switch, and remote access dial-up and virtual private network (VPN) connections. As a RADIUS proxy, IAS forwards authentication and accounting messages to other RADIUS servers

You can configure IAS in Windows Server 2003, Standard Edition, with a maximum of 50 RADIUS clients and a maximum of 2 remote RADIUS server groups. You can define a RADIUS client using a fully qualified domain name or an IP address, but you cannot define groups of RADIUS clients by specifying an IP address range. If the fully qualified domain name of a RADIUS client resolves to multiple IP addresses, the IAS server uses the first IP address returned in the DNS query. With IAS in Windows Server 2003, Enterprise Edition, and Windows Server 2003, Datacenter Edition, you can configure an unlimited number of RADIUS clients and remote RADIUS server groups. In addition, you can configure RADIUS clients by specifying an IP address range.

0
 
LVL 1

Author Comment

by:JakeWSYSA
Comment Utility
So, in my senario. I have volunteer administers that need access to corporate resources.  They dial-in using vpn and are authenticated.  The Users that have identical windows username/passwords set can access resources, however the users that have no username/passwords matching thier coroporate passwords get logged in as guest.  I have IAS already installed and one rule is listed and i believe this could be my problem.

"Use Windows authentication for all users"

In the case of the remote users I would rather use thier VPN username/password for local resources.  I tried adding a rule but it didn't work well, please help.

0
 
LVL 1

Accepted Solution

by:
012Uvongo earned 50 total points
Comment Utility
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This video discusses moving either the default database or any database to a new volume.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now