Security Basics mailing list archives

Re: Disabling split tunnelling on an ssl vpn


From: Secure This <lists () securethis net>
Date: Fri, 08 Feb 2008 11:23:50 +0000

Thanks - that confirms what I thought. I now need to give some direction to our desktop guy as to how to go about locking down the laptops - but I haven't had much to do with configuring windows since doing my mcse on NT4 ;-)

Any suggestions or resources would be gratefully received.

Ronald van der Westen wrote:
This has actually nothing to do with the Juniper SSL appliance itself.
You have to configure the laptop and make sure that it is only
possible to connect to your company's portal.
Configuring split-tunneling on the SSL is only used with Network Connect.

What you need to do, is lock down the laptop itself and not the Juniper SSL.

Regards,
Ronald van der Westen

On Feb 7, 2008 12:33 PM, Secure This <lists () securethis net> wrote:
Hi, I have a new laptop build going into our financial company along
with a Juniper ssl vpn solution. We need to lock the laptops down so
that they only connect through to our company's network via the ssl vpn
rather than being able to browse the internet directly, or worse have
split tunnelling active.

Could anybody kindly suggest approaches to this - It's been a while
since I have configured a Juniper ssl vpn appliance, but I'm guessing
most of it will need to be done on the locked down laptop build. I am
also mindful that some developers may be given local admin rights on
their laptop which complicates things.

Any help appreciated.....






Current thread: