David H. Posted September 24, 2008 Report Share Posted September 24, 2008 Hi, Here's our situation: We need to set up a GPO (can't think of any other option) that would recognize whether the user (using company's notebook) is at home or at work on our LAN. Based on that, the relevant FW settings will apply. At home - Internet's blocked but the connection to our VPNAt work - FW is less restrictiveAnyone has experience with Domain profile/Standard profile settings in domain GPO?Or can you think of anything else?Many thanks guys. Quote Link to comment Share on other sites More sharing options...
Irene Posted September 24, 2008 Report Share Posted September 24, 2008 Hello David, welcome to the forum. :D I am not experienced in this field, but I wonder if THIS is any help at all.Please post back with your views.. feedback is always useful.Hopefully, someone with more know of this topic will be able to help further. :) Quote Link to comment Share on other sites More sharing options...
David H. Posted September 25, 2008 Author Report Share Posted September 25, 2008 Hi Irene, Thanks, I do know about FW profiles, I forgot to mention that it is 2000 domain :-( which doesn't support FW profiles (I believe). Can't think of any other way how to change FW settings based on location (work/home)....Can anyone else? Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted September 25, 2008 Report Share Posted September 25, 2008 Hi David H.The solution to your problem may lie more with your VPN Client configuration than with firewall settings. You want to disallow split tunneling for VPN users. That means all traffic on a computer that is VPN'ed into your company will have to use the VPN tunnel. [edit]Split tunneling is kind of a Nortel term for this. Cisco calls it Remote Gateway, I believe.Split tunneling allows a VPN users computer to either access network resources like servers and e-mail through the tunnel, and to access the Internet outside the tunnel via their home router. It sounds like you want to make all traffic use the tunnel when users are VPN'ing. Quote Link to comment Share on other sites More sharing options...
David H. Posted September 26, 2008 Author Report Share Posted September 26, 2008 Hi homecomputeraid, Thanks a lot for your input, VPN might add some complications to our scenario...I work in a bank and we face a huge dilema now. There's a business pressure to come up with solution that will allow our users to use company's notebooks at home (using home broadband). Internet access for them must be blocked at home except our https://ssl.xxxx.yy website (Citrix gateway) - then it's all citrix = screen shots for them. But next day when they are at work, they mustn't be restricted in terms of accessibility at all.So somehow it must be detected they are at home -> restricted settings and once at work-> normal settings. They will still use (cached) domain account at home. To make it worse, it's still Windows 2000 domain :-(Back to your answer, I'm not sure how VPN element would help with that, please elaborate if you can.Thanks a lot for your time ;-)D. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted September 29, 2008 Report Share Posted September 29, 2008 I don't have much experience with SSL VPN's. I'm not sure how you can restrict all network traffic as you're trying to do. Perhaps you can look into paid 3rd party firewalls, or contact the VPN vendor? Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.