Re: how to secure VPN to a SQL server?



It does not matter if they have a dynamic IP address. The IP filtering I am
talking about is done post VPN after decryption by the VPN server on the IP
addresses that your RRAS assigns to them via DHCP or pool and Remote Access
Policies can be configured so that they apply based on user group membership
so that you can have different Remote Access Policy for different groups so
you could simply filter every user that matches a particular Remote Access
Policy. The trick for Remote Access Policies is to order then from specific
to general as the first one that applies to the connection will be used.
Since it seems you want to filter all VPN connections however you need to
only configure the default Remote Access Policy with the filtering you want
and yes it can be very restrictive though users do need access to DHCP/DNS
[unless RRAS does that] and domain controller if there is one. It would be
easy to restrict traffic to the IP of the SQL server. The link below
explains a little on configuring Remote Access Policy but in your case you
want to manage the input/output filters in the IP page. --- Steve

http://www.windowsecurity.com/articles/Securing_Remote_Access_Connections.html

"Rob R. Ainscough" <robains@xxxxxxxxxxx> wrote in message
news:e6SDiE9mGHA.1272@xxxxxxxxxxxxxxxxxxxxxxx
Steven,

Thanks for the response, unfortunately my situation is:

1. Some remote clients don't have static IPs (so filtering option on the
VPN server is out)
2. no guarantee the client has anything other than default XP admin
account (they also have legacy software that requires Admin)

Is there any way to restrict the VPN server to only support SQL traffic?

Thanks, Rob.


"Steven L Umbach" <n9rou@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:unBFLf8mGHA.4620@xxxxxxxxxxxxxxxxxxxxxxx
While using virus protection is a great idea there are other things you
should also do. If at all possible the users on the remote computer
should never be in the local administrators or power users group and
Software Restriction Policies can be implemented on XP Pro to control
what applications users do use and minimize the threat of malware. The
link below explains SRP in detail. You should also take advantage of
filtering capabilities of your VPN server to restrict what IP addresses
the VPN user can access and then what ports/protocols they are allowed to
access on those IP addresses. In Windows 2000/2003 RRAS you can configure
input/output filters in Remote Access Policy via edit profile - tcp/ip.
Of course the SQL server must be hardened including that the users have
only the needed permissions to do their job. --- Steve

http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/rstrplcy.mspx

"Rob R. Ainscough" <robains@xxxxxxxxxxx> wrote in message
news:uharm6vmGHA.4836@xxxxxxxxxxxxxxxxxxxxxxx
I have a deployment package that automatically sets up a VPN on a remote
client PC (public). What I'm concerned about is the client PC obtaining
a virus and that virus finding its way to our server via the VPN. The
client PC's do need Internet access & Email access while the VPN is
enabled. The VPN is used only for communication with the SQL server --
basically a split tunnel VPN solution. (TCP/IP settings, Use default
gateway on remote network is NOT checked)

What are my options?

Thanks, Rob.









.



Relevant Pages

  • Re: How to restrict clients on VPN
    ... traffic from a "public" ip address while remote access policy ip filtering ... > firewall/packet filtering rule to control access to your vpn server. ... > similar in rras via remote access policies where you could edit the ...
    (microsoft.public.win2000.security)
  • Re: Cant access resources on Windows XP VPN server
    ... How to Setup Windows, Network, VPN & Remote Access on "Rev Ingram" < ... PC seems to have several, there is the one on it's local network 192,168,2,X ... I've got a pc at church acting as a VPN server and have ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Weird VPN things
    ... Can you ping the VPN server? ... How to Setup Windows, Network, VPN & Remote Access on "Don Puspos" <Don ... The VPN server may be unreacheable or security ... * older user accounts that cannot connect when added to RAS group ...
    (microsoft.public.windows.server.networking)
  • Remote Access
    ... We are setting up remote access that uses ISA's VPN facility (rather than ... teh router's vpn server). ... is it possible to set ISA server to only accept connections from ...
    (microsoft.public.windows.server.sbs)
  • Server 2003 VPN / Client gives 678 error
    ... I am trying to use a Windows 2003 Server, who is already configured, as ... a VPN Server. ... I enabled VPN Gateway for the networkdevice ... In Routing and Remote Access I created a rule for vpn ...
    (microsoft.public.windows.server.networking)