Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

W2K - VPN & OWA

Thread Tools
 
Search this Thread
 
Old Aug 20, 2003 | 02:17 PM
  #1  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Thread Starter
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Question

Maybe I've forgotten summat but is it possible to allow OWA access to a user but NOT VPN?

'cos it seems to me that you can't...

I'm not sure that setting up a policy in RAS will overcome this problem but I may be wrong, 'cos I think that it is both an OWA & VPN thingy...


Ideas?
Reply
Old Aug 20, 2003 | 02:30 PM
  #2  
Chris L's Avatar
Chris L
Scooby Regular
 
Joined: May 2000
Posts: 10,371
Likes: 0
From: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Question

James

Are you talking about some form of split tunneling, with a connection to the internet and and an encrypted connection to your office network?

Chris
Reply
Old Aug 20, 2003 | 02:42 PM
  #3  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Thread Starter
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Post

Not really - want the user to be able to use OWA from home

Don't want the user to be able to VPN into the office & use shared resources that way
Reply
Old Aug 20, 2003 | 02:52 PM
  #4  
ozzy's Avatar
ozzy
Scooby Regular
 
Joined: Nov 1999
Posts: 10,504
Likes: 1
From: Scotland, UK
Post

They need a way into your LAN, so either it's port-forwarding on your firewall to the OWA box, VPN tunneling or some form of dial-up (RAS, Shiva box, etc..)

Can't think of any other ways at the moment.

Stefan
Reply
Old Aug 20, 2003 | 04:24 PM
  #5  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Allow access to the OWA server as if it was a Web Server ???
Reply
Old Aug 20, 2003 | 04:30 PM
  #6  
jpmason33's Avatar
jpmason33
Scooby Regular
 
Joined: Mar 2003
Posts: 831
Likes: 0
From: LA LA Land
Post

We run OWA here in the office yet Routing and remote access is not configured.

Do a port redirection on the firewall for port 80 (http) to the webserver that runs OWA. (ensuring you are pointing to the correct IP if the server has more than one!)

Then the user points the webbrowser at the IP address and the Virtual Directory for exchnage

For example (internal class C address for the example)
http://192.168.10.1/exchange

This will then require the user to authenticate using domain ID and Password ( have seen it a few times that the users must enter username of "DOMAIN\Username")

Hope this helps

J

Reply
Old Aug 20, 2003 | 06:06 PM
  #7  
HHxx's Avatar
HHxx
Scooby Regular
 
Joined: Nov 2001
Posts: 2,576
Likes: 0
Post

We do what James wants I think?

Certain vpn users are allowed access to a subset of servers using certain ports.

I suppose you want a owa user access to the exchange server on port 80 only?

We do this with Firewall1 rules, can't remember what vpn setup you have though :-|

H
Reply
Old Aug 20, 2003 | 06:16 PM
  #8  
ozzy's Avatar
ozzy
Scooby Regular
 
Joined: Nov 1999
Posts: 10,504
Likes: 1
From: Scotland, UK
Post

If you use a VPN you don't need port-forwarding. Ideally you'd want to use a VPN, but restrict the users access using the firewall configuration. All depends on which firewall you're using and if your VPN and Firewall service is provided by one server.

Port forwarding isn't the most secure and ideally you want it in a DMZ if you have to use it. I would also suggest changing the default listening port to something uncommon. This is a simple way to avoid anyone having a go if the only scan well known ports.

We use port-forwarding ourselves as the users don't want to use VPN's since they may want to access e-mail from customer sites or even an Internet Cafe.

Stefan
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
ozzy
Computer & Technology Related
9
Oct 28, 2002 10:57 AM
father_jack
Computer & Technology Related
4
Oct 7, 2002 12:30 PM
ChristianR
Computer & Technology Related
12
Sep 9, 2002 03:47 PM
IanWatson
Computer & Technology Related
12
Jul 31, 2002 10:37 PM
J T
Computer & Technology Related
9
Jun 20, 2002 12:10 PM




All times are GMT +1. The time now is 02:11 AM.