Re: How to prevent certain users from using VPN?

From: Andrew (aerginbas@hotmail.com)
Date: 12/19/02


From: "Andrew" <aerginbas@hotmail.com>
Date: Thu, 19 Dec 2002 20:49:30 +1100


Have a look at Remote-access permissions of the user account and/or
remote-access policies of RAS server.
Andrew

"Lars Knutsen" <larsk@sysedata-no-spam.no> wrote in message
news:C7eM9.2589$CG6.43747@news4.e.nsc.no...
> Cisco VPN concentrator is set up to require the user to have a certificate
> (MS certificate).
> It also prompts the user to enter logon credentials, this is the users
> username/password in the Win2000 AD.
>
> Now... as far as I can see... ANY user in AD can log on via VPN from ANY
> computer with a valid certificate?
>
> What I want to do is to allow only certain users to be able to use VPN.
> And thus deny certain users from using VPN *even* if they are using a
> computer with a valid certificate.
>
> Is this possible?
> I cant seem to find this documented anywhere.
>
>
> Lars Knutsen
>
>



Relevant Pages

  • problem with certificate of security
    ... I create and I install a valid certificate of security to be able to accede ... to my network win 2000 through one vpn. ...
    (microsoft.public.win2000.security)
  • How to prevent certain users from using VPN?
    ... Cisco VPN concentrator is set up to require the user to have a certificate ... It also prompts the user to enter logon credentials, ... ANY user in AD can log on via VPN from ANY ... computer with a valid certificate? ...
    (microsoft.public.win2000.security)
  • Re: How to prevent certain users from using VPN?
    ... > Have a look at Remote-access permissions of the user account and/or ... >> computer with a valid certificate? ...
    (microsoft.public.win2000.security)
  • Re: VPN concentrator placement
    ... Out on it's own DMZ would be nice. ... incoming VPN traffic as reasonably untrusted. ... I am doing a new install of a Cisco VPN concentrator on our existing ... that contains a checkpoint firewall. ...
    (Security-Basics)
  • [Full-Disclosure] MSNQwest ships DSL modem with "unconfigurable" firewall
    ... Real quick...just implemented a Cisco VPN concentrator here and lo and ... standard UDP port 500. ... the firewall on the DSL router they ship is "unconfigurable"...odd that it ... allowed Windows VPN TCP port 1723 but not UDP 500. ...
    (Full-Disclosure)