Koozali.org: home of the SME Server

VPN question

Arby Edi

VPN question
« on: August 14, 2002, 01:20:12 AM »
When I VPN from home (Win98 or WinXP) into our office SME 5.1.2 does all my internet activity, including browsing) first go out through the VPN into the office server and from there go out to the internet. or does it all just go through the net like "normal" without the VPN link?

And if it does go through teh VPN server frist then out to the net from the office and then return to me, does the sme basically act like a proxy and can I install proxy /filtering software on the sme 5.1.2 for al VPN traffic?

TIA.

Steve Bush

Re: VPN question
« Reply #1 on: August 14, 2002, 01:26:57 AM »
There is a setting in dial-up networking properties for the VPN connection.
Choose the networking tab>tcp/ip>properties>advanced either check or uncheck, use default gateway on remote network.  The default is to use the connection as the default gateway.

Arby Edi

Re: VPN question
« Reply #2 on: August 14, 2002, 01:44:54 AM »
The scary part is, I think I knew that.  Thanx though.
Any thoughts on the filtering part though?
It would make sense woudn't it, since it goes from Home->SME->gateway  back from gateway->SME->Home that the SME should be able to do filtering that way right?

Steve Bush

Re: VPN question
« Reply #3 on: August 14, 2002, 08:34:21 AM »
It makes sense to me....
You could try doing a traceroute with it checked and unchecked to verify.

ryan

Re: VPN question
« Reply #4 on: August 15, 2002, 10:35:06 AM »
I several SME 5.1.2 servers at work that I vpn to from home.  When I surf with the vpn connected, all web traffic goes through the vpn connection.  This is considerably slower (to encryption overhead i believe).  I have checked my IP address assigned during a vpn connection.  I surfed the web and found that the squid logs did not record the access.  Squidguard also failed to block offensive material sites when connected by VPN.  

ryan

Arby Edi

Re: VPN question
« Reply #5 on: August 16, 2002, 10:46:01 PM »
Thanx Ryan, saved me from doing a test.  I wonder why that is though since it needs to go through the box and through the gateway anyway like other traffic unless it enter on the other side of squid.(?)