RE: Modifying default behaviour of MS VPN client

From: Wozny, Scott (US - New York) (swozny_at_deloitte.com)
Date: 12/08/04

  • Next message: Paul Aviles: "RE: Modifying default behaviour of MS VPN client"
    Date: Wed, 8 Dec 2004 12:01:25 -0500
    To: "Paul Aviles" <paviles@adjoined.com>, <focus-ms@securityfocus.com>
    
    

    We've implemented this already to prevent users from saving their
    passwords. The problem is not that. If I enter NO username or
    password, the client will go back to the cached login credentials and
    try those which, lo and behold, work as the VPN server is authenticating
    to AD. What I need is a way to tell the client NOT to use cached
    credentials when told to connect with no user name and password.

    Thanks,

    Scott

    -----Original Message-----
    From: Paul Aviles [mailto:paviles@adjoined.com]
    Sent: Wednesday, December 08, 2004 11:57 AM
    To: Wozny, Scott (US - New York); focus-ms@securityfocus.com
    Subject: RE: Modifying default behaviour of MS VPN client

    Merge this on the registry, it will force the user to enter a user name
    and password and they cannot save the password.

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters]
    "DisableSavePassword"=dword:00000001

    -----Original Message-----
    From: Wozny, Scott (US - New York) [mailto:swozny@deloitte.com]
    Sent: Wednesday, December 08, 2004 10:24 AM
    To: focus-ms@securityfocus.com
    Subject: Modifying default behaviour of MS VPN client

    I have a situation on my hands where users have no username and password
    info in the MS VPN connection dialog but when they hit connect the
    client will use the username and password of the currently logged on
    user which grants them a successful authentication. Anyone know how to
    disable this behaviour and require that the user explicitly enter their
    username and password in the connection dialog for each VPN connection?

    Thanks,

    Scott

    This message (including any attachments) contains confidential
    information intended for a specific individual and purpose, and is
    protected by law. If you are not the intended recipient, you should
    delete this message. Any disclosure, copying, or distribution of this
    message, or the taking of any action based on it, is strictly
    prohibited.

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law.  If you are not the intended recipient, you should delete this message.  Any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited.
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Paul Aviles: "RE: Modifying default behaviour of MS VPN client"

    Relevant Pages

    • Re: VPN via Wireless Broadband
      ... I don't know how timing-sensitive VPN connections are. ... Browsing to the User shared folder from the client doesn't work. ... shares on the server and SYSVOL is there and one can use Windows ... How to configure a VPN connection to your corporate network in Windows XP ...
      (microsoft.public.windows.server.sbs)
    • Re: Remote accessing file shares problem
      ... Since I don't have controll/access to the concentrator, ... Did the Cisco client has the similar function as MS VPN client that "Log ... In the Configuration of the Dialup Connection (the VPN Connection) ...
      (microsoft.public.windows.server.networking)
    • RE: VPN - SBS2003
      ... I understand that the remote client cannot connect to ... What error information did you receive when the VPN terminated? ... Can you establish the VPN connection to the SBS Server from internal ...
      (microsoft.public.windows.server.sbs)
    • Re: VPN Issue
      ... I have read some articles about this subnet issue, so I know what you mean. ... I then connect to my network using the VPN connectoid. ... a new network adapter in the client directly to one in the server. ... But ONLY if I add in the domain.local DNS suffix to the VPN connection. ...
      (microsoft.public.windows.server.sbs)
    • RE: error 628 in vpn
      ... firewall blocks the VPN traffic. ... is used when you want to enable remote access if your remote client ... As you mentioned the VPN connection can be made from a SBS LAN ... client, the configuration of the RRAS itself should be OK. ...
      (microsoft.public.windows.server.sbs)