Re: VPNs over NoCatAuth
Steve Wright <[email protected]>
| Newsgroups | gmane.network.nocat |
|---|---|
| Message-ID | <[email protected]> |
I would have thought the route to the local address would remain in place, and that the client would use that route since it was more specific than the default route via the VPN. After all, how would the client route to the VPN server if if id didnt have a valid route.. so why can it not route to the auth server? Steve On Tue, 2005-01-11 at 23:53, Schuyler Erle wrote: > * On 10-Jan-2005 at 11:42AM PST, Brendan Miller said: > > > > If I manually permit (using the fw_exception script) the IP and MAC of the > > VPN user, his VPN works perfectly, albeit he is not subjected to the splash > > page and has no renewal window with which to contend. We would like to keep > > the splash page/renewal process intact--how can we handle the VPN tunnel > > situation? > > I fear that there is not much to be done about this on the gateway > side. Obviously you can't intercept specific VPN connections, so you > need to find some way to keep users from having their gateway for > local network connections go down the VPN. How you accomplish this I > cannot guess, sorry. :-/ > > SDE > _______________________________________________ > NoCat mailing list > [email protected] > http://lists.nocat.net/mailman/listinfo/nocat