Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Stopping VPN split tunnelling

Posted on 2015-01-05
6
Medium Priority
?
591 Views
Last Modified: 2015-01-08
I have a client which has a draytek vigor 2860 firewall router which is setup for VPN connections.

They have had an IT audit (by their major client) and they must implement controls to prohibit split tunnelling during remote access. The problem is that i need to access their network via VPN on a PC. I understand that by default split tunneling is turned off when creating a vpn connection in windows and usually you would control these setting and lock them down via group policy. My machine isn't part of their network so it cannot be controlled, so i could just enable split tunnelling if i wanted. Is there a VPN client or a setting on the draytek router, where i could lock down VPN settings (prohibit split tunnelling) or use some sort of software to have these settings included and not easily changed by a user on a vpn client?? Or do i need to implement another solution?

Thanks for your help.

Riccardo
0
Comment
Question by:RiccardoQuest
  • 3
  • 3
6 Comments
 
LVL 50

Expert Comment

by:Don Johnston
ID: 40531411
Split tunneling is configured on the VPN concentrator (or firewall or whatever device you  are establishing the tunnel to).  It is not configured on the remote access computer.

Is there a reason you want split tunneling?
0
 

Author Comment

by:RiccardoQuest
ID: 40531417
i don't want split tunnelling, i want a method of locking down the client machine settings so they cannot change their settings on their local machines and then enable split tunnelling?
0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 40531423
Clients can't choose between split tunneling and hair pinning.  That's determined on the other end of the tunnel.
0
Ready for your healthcare security check-up?

In the past few years, healthcare organizations have become a prime target for advanced attacks. Does your organization have what it needs to defend itself? Schedule your healthcare security check-up today and download our free Healthcare Security Resource Kit today!

 

Author Comment

by:RiccardoQuest
ID: 40531434
i understand that if you follow the steps in the below link, that will enable a split tunnel (at the client end) which could have adverse effects on the other network (the one connected via VPN). These settings are all controlled at the client machine.

https://kb.meraki.com/knowledge_base/configuring-split-tunnel-client-vpn-on-windows-and-mac-os-x
0
 
LVL 50

Accepted Solution

by:
Don Johnston earned 2000 total points
ID: 40531655
Okay, I see where you're going now. Sorry.

The thing is, that there are many ways of circumventing a VPN which is not configured for split tunneling.  And most of those methods can not be prevented from the HQ side unless they have control over the host.  For example, if it's a company PC, you can lock it down to prevent changes to the configuration or installation of applications which could bypass the "no split tunnel" rules.

If not, there's not much you can do to enforce that.  For example, on my laptop, I have a wired and wireless NIC.  If I use the Cisco VPN client to establish a VPN over the wired NIC, But I can still browse the internet over the wireless NIC.  So having split tunneling disabled isn't stopping me from having my own, unsecured, internet connection.
0
 

Author Comment

by:RiccardoQuest
ID: 40538180
Thanks for your help! I now understand that to fully prevent split tunneling, restrictions need to be applied to the host machine stopping additional hardware being added as well as restricting VPN connectivity setting using Group Policies.
0

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question