Link to home
Start Free TrialLog in
Avatar of R4inc
R4inc

asked on

How to setup routing table through VPN

My network has many different VLANs and we have users VPN from time to time.  they need to access information on different networks through the VPN, which is allowed through the VLANs they are accessing, but since the IP subnet is different from the VPN they cannot access.  I am able to setup a script that will set the routing statements on their computer after they connect, but is there a way to do this on the server?  I want them to be able to access the other VLANs when connected through VPN and right now they cannot.  
Avatar of R4inc
R4inc

ASKER

To give more information, we have subnet A: 192.168.99.0/24 and subnet B: 192.168.100.0/24.  VPN comes into subnet A and gives an address from Subnet A.  They cannot access subnet B because their default route would send it out through their ISP.  Not all PCs are joined to the domain or under my control since some are MACs.  It is just a hassle to have the user run a script when they connect.  Servers are Windows 2008.
Hi,

You can normally configure split tunnelling. What hardware are you using? If it's cisco you can configure an access-list which defines the networks that can be reached through the VPN.
Avatar of R4inc

ASKER

We are just using RRAS through Server 2008.
When they connect to the VPN, do they get a default route which pushes everything through the VPN?
ASKER CERTIFIED SOLUTION
Avatar of rochey2009
rochey2009

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of R4inc

ASKER

That's it I believe.  The setup is to uncheck that box so they get Internet at the same time as VPN.  Never heard of split tunneling.  Good to know and will fix that ASAP.  I will try VPN this way tonight to see if it fixes the problem.  Thanks!
Avatar of R4inc

ASKER

Is there a way to set this through Group Policy?
I'm not sure about the group policy but I would think it's possible. You should also be aware of the security implications of enabling split tunnelling.
Avatar of R4inc

ASKER

I am now aware and I want to use GP to disable this if possible.  The setup I found in GP will not allow me to edit the Advanced settings for the VPN connection so I guess I will have to get to every PC in the org...