09-10-2014 01:36 AM - edited 03-11-2019 09:44 PM
Hi,
we have requirement that remote users want to use corporate application like file server etc and at the same time they also want to use internet on their system
what are the options available on firewall to configure this.
what kind of security threats and vulnerability challenges wil be there if user access application and internet at same time
if possible please provide solution with explanation.
regards
rajat
09-10-2014 02:19 AM
In general: If the client can directly communicate with the internet, it's easier for an attacker to use that PC as a jump-point into the network or to compromise the client. The typical solutions to give VPN-clients internet-access are:
09-10-2014 07:10 AM
hi karsten,
can you elaborate little bit of first solution and second more . please share any practical scenario or any implementation guide if you have. looking forward for your valuable thoughts and suggestion
regards
rajat
09-10-2014 11:07 PM
hi,
can any body provide split tunnelin example on asa version 9.1
regards
rajat
09-10-2014 11:18 PM
Hi Rajat,
You can refer the below link for a config example with explaination.
http://www.petenetlive.com/KB/Article/0000943.htm
Regards
Karthik
09-10-2014 04:30 AM
Hi,
In case if you have a sufficient bandwidth available in your office network, go with tunnel all and make everything to go via your office network.... so that you can keep a track on internet..... else another option is to do with split-tunnel for your vpn.... only office lan network will flow through vpn and rest will flow through their local gateway..... means all traffic related to office lan.... whatever you have in internal lan or vpn acl..... it will have routed to vpn gateway and all other ( 0.0.0.0) route will go via local gateway of the end user ISP.....
If you take things via office network.... you can limit / block the unnecessary ports or protocols to access..... you can keep the content filtering / proxy servers in inside lan to block black listed sites or malware sites......
Regards
Karthik
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide