Jump to content

How to apply Windows Firewall depending on location (work/home)


David H.
 Share

Recommended Posts

Hi,

Here's our situation: We need to set up a GPO (can't think of any other option) that would recognize whether the user (using company's notebook) is at home or at work on our LAN. Based on that, the relevant FW settings will apply.

At home - Internet's blocked but the connection to our VPN

At work - FW is less restrictive

Anyone has experience with Domain profile/Standard profile settings in domain GPO?

Or can you think of anything else?

Many thanks guys.

Link to comment
Share on other sites

Hello David, welcome to the forum. :D

I am not experienced in this field, but I wonder if THIS is any help at all.

Please post back with your views.. feedback is always useful.

Hopefully, someone with more know of this topic will be able to help further. :)

Link to comment
Share on other sites

Hi David H.

The solution to your problem may lie more with your VPN Client configuration than with firewall settings. You want to disallow split tunneling for VPN users. That means all traffic on a computer that is VPN'ed into your company will have to use the VPN tunnel.

[edit]Split tunneling is kind of a Nortel term for this. Cisco calls it Remote Gateway, I believe.

Split tunneling allows a VPN users computer to either access network resources like servers and e-mail through the tunnel, and to access the Internet outside the tunnel via their home router. It sounds like you want to make all traffic use the tunnel when users are VPN'ing.

Link to comment
Share on other sites

Hi homecomputeraid,

Thanks a lot for your input, VPN might add some complications to our scenario...

I work in a bank and we face a huge dilema now. There's a business pressure to come up with solution that will allow our users to use company's notebooks at home (using home broadband). Internet access for them must be blocked at home except our https://ssl.xxxx.yy website (Citrix gateway) - then it's all citrix = screen shots for them.

But next day when they are at work, they mustn't be restricted in terms of accessibility at all.

So somehow it must be detected they are at home -> restricted settings and once at work-> normal settings. They will still use (cached) domain account at home. To make it worse, it's still Windows 2000 domain :-(

Back to your answer, I'm not sure how VPN element would help with that, please elaborate if you can.

Thanks a lot for your time ;-)

D.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy