Link to home
Start Free TrialLog in
Avatar of JakeWSYSA
JakeWSYSA

asked on

VPN users authenticate as guests for network resources.

Hi,
I am running windows 2003 server and have VPN setup on a machine, Users can access VPN, connect to our outbound internet and access our internal resources, however they are authenticated as Guests and thus have limited access to network resources.  What is happening here.  

This is the second time this problem has occurred.  
Once on windows 2000
and another time on windows XP

Both PC's do not have a (login)password set.

I want to allow these individuals to connect without requireing them to change thier username/password to match our internal network.
Avatar of 012Uvongo
012Uvongo


Hey mate

Your VPN server is it a standalone server? How do users obtain an IP address through the RRAS server or through the DHCP server?

Have you tried IAS?

Internet Authentication Service (IAS) in Microsoft® Windows Server 2003, Standard Edition; Windows Server 2003, Enterprise Edition; and Windows Server 2003, Datacenter Edition is the Microsoft implementation of a Remote Authentication Dial-in User Service (RADIUS) server and proxy. As a RADIUS server, IAS performs centralized connection authentication, authorization, and accounting for many types of network access including wireless, authenticating switch, and remote access dial-up and virtual private network (VPN) connections. As a RADIUS proxy, IAS forwards authentication and accounting messages to other RADIUS servers

You can configure IAS in Windows Server 2003, Standard Edition, with a maximum of 50 RADIUS clients and a maximum of 2 remote RADIUS server groups. You can define a RADIUS client using a fully qualified domain name or an IP address, but you cannot define groups of RADIUS clients by specifying an IP address range. If the fully qualified domain name of a RADIUS client resolves to multiple IP addresses, the IAS server uses the first IP address returned in the DNS query. With IAS in Windows Server 2003, Enterprise Edition, and Windows Server 2003, Datacenter Edition, you can configure an unlimited number of RADIUS clients and remote RADIUS server groups. In addition, you can configure RADIUS clients by specifying an IP address range.

Avatar of JakeWSYSA

ASKER

So, in my senario. I have volunteer administers that need access to corporate resources.  They dial-in using vpn and are authenticated.  The Users that have identical windows username/passwords set can access resources, however the users that have no username/passwords matching thier coroporate passwords get logged in as guest.  I have IAS already installed and one rule is listed and i believe this could be my problem.

"Use Windows authentication for all users"

In the case of the remote users I would rather use thier VPN username/password for local resources.  I tried adding a rule but it didn't work well, please help.

ASKER CERTIFIED SOLUTION
Avatar of 012Uvongo
012Uvongo

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial