Re: VPNs over NoCatAuth

Brendan Miller <[email protected]>
Newsgroups gmane.network.nocat
Message-ID <[email protected]>
My understanding is that the actual physical network adapter and its routes
are "covered up" by the software client-imposed VPN routes.  I've never looked
at the Windows routing table (can you?) with a VPN client, as I spend very 
little time in Windows.  But my limited experience with Windows VPNs is that
the client takes over and forces all traffic down the tunnel...

Brendan

On Fri, Jan 14, 2005 at 08:47:53AM +1300, Steve Wright wrote:
> I would have thought the route to the local address would remain in
> place, and that the client would use that route since it was more
> specific than the default route via the VPN.  After all, how would the
> client route to the VPN server if if id didnt have a valid route.. so
> why can it not route to the auth server?
> 
> Steve
> 
> On Tue, 2005-01-11 at 23:53, Schuyler Erle wrote:
> 
> > * On 10-Jan-2005 at 11:42AM PST, Brendan Miller said:
> > > 
> > > If I manually permit (using the fw_exception script) the IP and MAC of the 
> > > VPN user, his VPN works perfectly, albeit he is not subjected to the splash
> > > page and has no renewal window with which to contend.  We would like to keep
> > > the splash page/renewal process intact--how can we handle the VPN tunnel
> > > situation?
> > 
> > I fear that there is not much to be done about this on the gateway
> > side. Obviously you can't intercept specific VPN connections, so you
> > need to find some way to keep users from having their gateway for
> > local network connections go down the VPN. How you accomplish this I
> > cannot guess, sorry. :-/
> > 
> > SDE
> > _______________________________________________
> > NoCat mailing list
> > [email protected]
> > http://lists.nocat.net/mailman/listinfo/nocat
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.