Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > VPN and local LAN access with 2 nics

Reply
Thread Tools

VPN and local LAN access with 2 nics

 
 
Roman Kab
Guest
Posts: n/a
 
      12-03-2003
Hello,

Is it possible to configure a VPN client in the PC with 2 nics and
retain local area network access.

My PC has 2 nics connected to one router ( DLINK ) and use 192.168.0.x
ips.
I wanted to configure VPN software to use one card to access corporate
network and the second card to retain acces to my local lan and
network printers.

Corporate lan has disabled split tunnel feature.

I tried once but lost local lan access as soon as VPN connection was
enabled.

Any suggestions?

Thanks
Roman
 
Reply With Quote
 
 
 
 
John Smith
Guest
Posts: n/a
 
      12-03-2003
Think outside the TCP/IP box!

Bind multiple protocols to your Internal NIC (i.e. TCP/IP and IPX).
Setup VPN as normal, it will only control TCP/IP (split tunneling).
Connect to your shares and printers using IPX (remember to specify the frame
type for IPX on each box (autodetection doesn't always work)).


"Roman Kab" <> wrote in message
news: om...
> Hello,
>
> Is it possible to configure a VPN client in the PC with 2 nics and
> retain local area network access.
>
> My PC has 2 nics connected to one router ( DLINK ) and use 192.168.0.x
> ips.
> I wanted to configure VPN software to use one card to access corporate
> network and the second card to retain acces to my local lan and
> network printers.
>
> Corporate lan has disabled split tunnel feature.
>
> I tried once but lost local lan access as soon as VPN connection was
> enabled.
>
> Any suggestions?
>
> Thanks
> Roman



 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      12-03-2003
In article < >,
Roman Kab <> wrote:
:Is it possible to configure a VPN client in the PC with 2 nics and
:retain local area network access.

:My PC has 2 nics connected to one router ( DLINK ) and use 192.168.0.x
:ips.
:I wanted to configure VPN software to use one card to access corporate
:network and the second card to retain acces to my local lan and
:network printers.

:Corporate lan has disabled split tunnel feature.

:I tried once but lost local lan access as soon as VPN connection was
:enabled.

:Any suggestions?

My suggestion would be to politely ask your network admins whether
they would enable split tunnel. If they will not, then my suggestion
would be that you not try to get around the block.

When you allow access to both networks at the same time, through any
mechanism, then your corporate lan becomes vulnerable to whatever
problems exist on the other lan, because viruses, worms, and trojans can
then use your PC as router or relay point. If your security people
have made a design decision to block split tunneling, then you endanger
the corporate network by bypassing their decision, and you risk
the corporate security people finding out and cracking the security
policy.

In some environments, deliberately bypassing a "no split tunnel"
rule would be grounds for immediate firing -and- being assessed the
cost of a thorough network security audit to find out what the impact
of the hole was.
--
Warhol's Second Law of Usenet: "In the future, everyone will troll
for 15 minutes."
 
Reply With Quote
 
John Smith
Guest
Posts: n/a
 
      12-04-2003
All well in good, however split tunneling is only for TCP/IP connectivity. They
would need to publish policies saying no alternate protocols and make that very
clear to the users before any firing would happen.

Not to mention the fact that this box may not even be their employees, but a
partners, hard to push your rules onto others sometimes for many reasons.

Besides, what happens once the VPN isn't being used? The risks you site can
still happen to the box while offline from the VPN, then expose your network too
them once they connect again. What controls do you have then for their home
LAN.

VPN segments should be firewalled as well in my opinion and treated as untrusted
inside the work network.



"Walter Roberson" <> wrote in message
news:bqle63$6tm$...
> In article < >,
> Roman Kab <> wrote:
> :Is it possible to configure a VPN client in the PC with 2 nics and
> :retain local area network access.
>
> :My PC has 2 nics connected to one router ( DLINK ) and use 192.168.0.x
> :ips.
> :I wanted to configure VPN software to use one card to access corporate
> :network and the second card to retain acces to my local lan and
> :network printers.
>
> :Corporate lan has disabled split tunnel feature.
>
> :I tried once but lost local lan access as soon as VPN connection was
> :enabled.
>
> :Any suggestions?
>
> My suggestion would be to politely ask your network admins whether
> they would enable split tunnel. If they will not, then my suggestion
> would be that you not try to get around the block.
>
> When you allow access to both networks at the same time, through any
> mechanism, then your corporate lan becomes vulnerable to whatever
> problems exist on the other lan, because viruses, worms, and trojans can
> then use your PC as router or relay point. If your security people
> have made a design decision to block split tunneling, then you endanger
> the corporate network by bypassing their decision, and you risk
> the corporate security people finding out and cracking the security
> policy.
>
> In some environments, deliberately bypassing a "no split tunnel"
> rule would be grounds for immediate firing -and- being assessed the
> cost of a thorough network security audit to find out what the impact
> of the hole was.
> --
> Warhol's Second Law of Usenet: "In the future, everyone will troll
> for 15 minutes."



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Cisco VPN client, local LAN access and second NIC Diego Balgera Cisco 2 03-14-2008 03:49 PM
Desktop w/ 3 NICs - Multiple VPN Connections - How to configure? mtangorre Computer Support 3 02-06-2008 09:11 AM
Local Lan Access on Windows Cisco VPN Version 5.0.00.0340 godshiva@gmail.com Cisco 0 07-11-2007 04:48 PM
Setup split tunnel to allow access to local lan using cisco vpn client Jon L. Miller Cisco 1 02-07-2005 09:00 PM
Local lan access with cisco 3.5.2 vpn client Gary Smith Cisco 0 01-15-2004 05:22 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57