Recommended Posts

Hi

When using pptp my external ip changes, but when using cisco ipsec vpn it stays the same however I can still connect to machines on the vpn. If i were to traceroute neowin, the traceroute wouldnt change from what i would normally see.

Does it only foward traffic through the vpn server for some hostnames? pptp seems to foward everything.

Thanks

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/
Share on other sites

Depends on if your vpn connection is setup to be the default gateway or not. Sounds like your cisco connection is allowing for split tunnel - which normally is a no no and companies do not allow for that

On your pptp/vpn connection you can check

post-14624-1258819886_thumb.png

I would post a picture for the cisco client, but don't feel like firing up my laptop, etc.

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591877194
Share on other sites

I am using a mac, when connecting to the vpn and visiting whatismyip.com it reports the same IP as when im not on the vpn. I have not changed any settings on the mac, however am definitely on the vpn as I can ping internal mail servers etc.

The exact same thing happens with the cisco client on windows but I cant find anything on either pc about split tunnel.. does cisco ipsec work out which hosts are on the vpn and only redirect their traffic?

Thanks

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591877390
Share on other sites

Does not matter what OS your on -- the settings for a vpn are the same, either use the remote gateway or not, and just route traffic to the connection. Only thing that would change is the where in some gui you would make the change, or maybe terms slightly different

The cisco client would be setup by the vpn admin on the other end if you can split tunnel or not.

On the cisco client it would be call allow local access or something like that - would have to fire up client.. And then again it might have changed terms a bit.. Which cisco client are you using? 5 I would guess.. Cisco is going to end support for the ipsec clients -- need to move to the anyclient which is all SSL based.

Just take a look at your route table when you connect to your vpn and you will see what will happen. A VPN can either route all traffic through the vpn connection, or it can just add a route to the other network(s) on the other end of the vpn.

When your allowed access to local network, using your local networks gateway and also the networks on the other end of a vpn its called a split tunnel.

http://en.wikipedia.org/wiki/Split_tunneling

Normally users don't want to have to route all traffic through a vpn to access internet, etc.. since normally home internet is faster than routing through the work network, and then using the works internet connection, etc.

Unless your wanting to circumvent something by routing the traffic through the vpn connection, and then some site seeing the vpns IP vs your local one -- I don't really see what your issue is? You stated you have access to the servers using the vpn.

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591877450
Share on other sites

It doesn't really know which hosts on there, it knows what networks are there.

If want to understand how it works, look up routing.

I don't have a mac, but fairly sure since os x is based off darwin that the command would be the same as it is in linux

netstat -nr

this will show you your routing table -- so run it when connected to the vpn and you will see how it knows to send your traffic down the vpn when you want to connect to machine housed at the other end of the vpn.

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591877666
Share on other sites

Normally users don't want to have to route all traffic through a vpn to access internet, etc.. since normally home internet is faster than routing through the work network, and then using the works internet connection, etc.

Unless your wanting to circumvent something by routing the traffic through the vpn connection, and then some site seeing the vpns IP vs your local one -- I don't really see what your issue is? You stated you have access to the servers using the vpn.

Some companies would want to block all external network connectivity when on the VPN, and to route all internet traffic via the VPN

1) so that there's no danger of the Local network the remote user is on interacting with the machine when it's on the Corporate network.

2) So that they can log/filter any internet access from the machine whilst it connected to the corporate network.

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591877710
Share on other sites

2) So that they can log/filter any internet access from the machine whilst it connected to the corporate network.

Why? If the internet isn't going through their vpn server and using the local connection instead then its not their problem, why waste bandwidth by sending it through their server?

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591877870
Share on other sites

Quite often you would want to filter the machines internet access if it connects to the work network - to protect it.. Which is why its rare to see split tunnel setups..

You would not want a work computer connecting to the public net unless its going through the company firewall and content filters, does not matter if the computer is at work or some other location.

Quite often you would block all internet access on roaming work machines other then to connect to the vpn -- and then through that connect to the internet through the controlled work connection.

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591878056
Share on other sites

Why? If the internet isn't going through their vpn server and using the local connection instead then its not their problem, why waste bandwidth by sending it through their server?

Because you probably don't want machines that are connected to your corporate network which probably has internal data on it users who have access to commercially sensitive information just running around on an unfiltered net connection.

Also by forcing them though the vpn as well as filter you can virus scan traffic at the gateway if you so wish.

Some Companies will also Mandate that the firewall software is installed and running before allowing access to the VPN and will then configure the firewall on the machine to drop all local network traffic so that the machine is only accessable by the VPN and not the network it is connected to.

It usually depends on how strict your IT department are some will let laptop users connect directly to the internet but only when not VPN'd or on their LAN, some will mandate all traffic goes via the VPN/Corp Network and some will probably allow split tunneling.

Link to comment
https://www.neowin.net/forum/topic/847882-ipsec-vpn/#findComment-591878088
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Firefox 152.0 by Razvan Serea Firefox is a fast, full-featured Web browser. It offers great security, privacy, and protection against viruses, spyware, malware, and it can also easily block pop-up windows. The key features that have made Firefox so popular are the simple and effective UI, browser speed and strong security capabilities. Firefox has complete features for browsing the Internet. It is very reliable and flexible due to its implemented security features, along with customization options. Firefox includes pop-up blocking, tab-browsing, integrated Google search, simplified privacy controls, a streamlined browser window that shows you more of the page than any other browser and a number of additional features that work with you to help you get the most out of your time online. Firefox key features Enhanced Tracking Protection (ETP) – Blocks trackers, cookies, cryptominers, and fingerprinters by default. Private Browsing Mode – Deletes history, cookies, and temporary files when closed. Lightweight & Fast Performance – Optimized memory usage with efficient page loading. Cross-Platform Sync – Sync bookmarks, passwords, history, and open tabs across devices. Customizable Interface – Toolbars, themes, and extensions can be tailored to user needs. Strong Privacy Controls – Options to manage cookies, permissions, and site data easily. Reader Mode – Strips away clutter for distraction-free reading. Pocket Integration – Save and read articles offline with Pocket built into Firefox. Picture-in-Picture (PiP) – Watch videos in a floating window while multitasking. Extensions & Add-ons – Vast library for productivity, security, and personalization. Built-in PDF Viewer – No need for external software to view PDFs. Firefox Monitor – Alerts users if their email is part of a known data breach. Multi-Account Containers – Isolate browsing sessions (e.g., work, personal, shopping). Performance & Resource Efficiency – Uses fewer system resources than some competitors. Open Source & Community-Driven – Transparent development with global contributions. Download: Firefox 64-bit | Firefox 32-bit | ARM64 | ~70.0 MB (Freeware) Download: Firefox for MacOS | 145.0 MB View: Firefox Home Page | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft Visio 2024 Professional for Windows is still at 90% off by Steven Parker Created by ChatGPT Today's highlighted Neowin Deal comes from our Apps & Software section of the Neowin Deals store, where you can save 90% on Microsoft Visio 2024 Professional for Windows [Digital License]. Microsoft Visio: Turn Complex Ideas into Clear Visuals Microsoft Visio 2024 is a robust diagramming software designed to empower individuals and businesses to visually represent complex data, processes, and workflows. With a host of advanced features, it caters to professionals from various industries, including IT, engineering, business, and architecture. Visio 2024 makes it easy for individuals and teams to create and share clear, professional diagrams that simplify complex information. It offers updated shapes, templates, and styles, along with a new search bar to improve your experience. Visio 2024 also has a fresh design that matches other Office apps you use. Create stunning diagrams Extensive Diagramming Capabilities: Visio 2024 offers a wide array of diagram types, including flowcharts, process maps, floor plans, network diagrams, and organizational charts. The software comes with a comprehensive set of pre-built templates and shapes, making it easier to get started on projects quickly. Professional Templates and Shapes: The software includes over 250,000 shapes across multiple diagram types, ensuring that users from any field-whether creating a simple flowchart or a complex engineering design-have the tools they need to represent their ideas visually. Data-Linked Diagrams: One of the most powerful features of Visio 2024 is its ability to link data to diagrams, allowing users to visualize real-time data directly within their diagrams. Whether you're pulling data from Excel, SQL Server, or other databases, the software ensures that your diagrams are automatically updated as data changes, giving users better insights and control. Advanced Formatting Options: Visio 2024 comes equipped with a range of formatting tools to create highly customized diagrams. These include shape formatting, text adjustments, and the ability to apply various themes, ensuring diagrams not only serve their functional purpose but also look professional. Enhanced Visual Styles: This version of Visio includes new visual styles and layouts that make complex diagrams easier to interpret. Whether you're designing an IT network, a business process flow, or a floor plan, the enhanced visual options improve clarity and presentation quality. Easy, secure collaboration Real-Time Collaboration: With Visio 2024's improved collaboration tools, multiple users can work on the same diagram simultaneously from anywhere, with changes being tracked in real-time. This makes it a highly efficient tool for teams working remotely or across different locations. Mobile and Cloud Access: Users can view and edit diagrams on the go with the Visio web app. This ensures that even when you're away from your desktop, you can access and make critical changes to diagrams via mobile devices. Integration with Microsoft 365: Visio 2024 integrates seamlessly with the Microsoft 365 suite, allowing users to easily embed diagrams into PowerPoint presentations, Word documents, or Teams chats. You can also store diagrams in OneDrive or SharePoint for easy sharing and access from any device. Security and Compliance: Built with enterprise-grade security, Visio 2024 ensures that your diagrams are protected. Microsoft's trusted cloud infrastructure means that your data is encrypted and safeguarded, with compliance with international standards. Good to know Length of access: lifetime Redemption deadline: redeem your code within 7 days of purchase Access options: desktop Bound to account - Limited to one device activation at a time Only available to existing and new users Version: 2024 Updates included Click here to verify Microsoft partnership Microsoft Visio 2024 Professional for Windows normally costs $579.99, but it can be yours for just $39.97 for a limited time, that's a saving of $520 (90%). For terms, specifications, and license info please click the link below. Microsoft Visio 2024 Professional for Windows for $54.97 (was $579.99) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • I totally disagree. Very little good comes out of governments all around the world manipulating everything they can and usually the people are not the benefactors. What you say about being restricted and expensive sounds almost like the arguments against firearms and why banning them will protect people as if making something illegal somehow will prevent the criminals from having and using them. AI being far less mainstream could simply mean the average person will not benefit, but "big brother" and the corporations will benefit, which is almost for sure NOT a good thing.
    • I do apologize to the author Mr. Sen for my rude comment, questioning his knowledge of the subject. It is I whom lacked knowledge of the subject. Sorry!
    • Hello All Have a MSI Pro B650 VC Wifi Rev 1.0 motherboard Ryzen 7 7700X Radeon 7800XT OC 16GB 32GB Teamgroup DDR 5 5600mhz Samsung 990 Pro 1TB Boot NVMe Samsung 990 Pro 2TB Game NVMe Lian Li Lancool Black ARGB 216 Case Seasonic Focus GX 750 Watt Power supply   Wondering today what is best spot to plug in the following items on system for performance and not bottle neck anything if i can help it Creative Pebble Pro USB C or A Speakers, ((Powered by External USB C to C PD Adapter)  Logitech G513 USB Gaming Keyboard Logitech G502X Wired Gaming Mouse Cyberpower UPS USB Cable for UPS Power Management/System shutdown External drives connected occasionally are as follows---WD My Book 8TB (primary backup drive)   Seagate 8TB in External USB 3.0 Enclosure,  Seagate Portable 1TB USB 3.0 drive,   WD My Passport (Blue) 2TB, and WD My Passport (Red) 2TB,    WD Elements 500GB USB 2.0 External (Oldest one, Christmas 2003)       **Do have a 7 Port Powered  USB Hub as well, but when i use that--that leaves only the USB Flash spot for something to directly connect to system if needed.    Rear USB C 2x2 unused right now as moved the Creative speakers off it to USB A port next to it, with a USB C to A Cable, as figured speakers didn't near audio from USB C port and tie up the high speed port**   Front Ports trying to limit use of, so i don't have Front I/O port go bad again, already had it replaced once by Lian Li support all the way from Taiwan over night ((Do get extra nervous at times on things,  so i might just be extra nervous for nothing lol))
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      497
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      127
    4. 4
      Steven P.
      82
    5. 5
      ATLien_0
      76
  • Tell a friend

    Love Neowin? Tell a friend!