Computing.Net > Forums > Windows Server 2003 > VPN users are logged in as GUEST for fileshar

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

VPN users are logged in as GUEST for fileshar

Reply to Message Icon

Name: RSXHiTMAN
Date: September 21, 2009 at 10:26:49 Pacific
OS: SERVER 2003
CPU/Ram: 2.7ghz /1024ram
Subcategory: Configurations
Tags: vpn, File Sharing, DENY, GUEST
Comment:

Im trying to restrict VPN users from accessing the local file shares, however im having trouble making a distinct separation, the shares are open to everyone, so i dont have to setup the local computers, but im trying to restrict VPN users from accessing the shares..the problem here is VPN users are logged in as GUEST accounts when they try to view a share, it would be nice to be able to DENY access to JUST the VPN GROUP



Sponsored Link
Ads by Google

Response Number 1
Name: wanderer
Date: September 21, 2009 at 11:52:07 Pacific
Reply:

not possible unless you are running active directory and a server. appears you are doing peer to peer networking.

Normally guest is not enabled anywhere.

Users would logon via their AD accounts. If you want to create a vpn group you can do so but you would also need to make secondary accounts for vpn users to use and these accounts would be included in the vpn group for share assignments.


0

Response Number 2
Name: RSXHiTMAN
Date: September 21, 2009 at 12:00:25 Pacific
Reply:

what do you mean peer to peer? the file shares are enabled to allow EVERYONE to read, VPN users when accessing the file shares are logged on as GUESTs, even though they have their own username and a vpn group which is denied to access these shares


0

Response Number 3
Name: wanderer
Date: September 21, 2009 at 12:14:30 Pacific
Reply:

peer to peer is defined as all hosts share among themselves [distributed]
server/client is defined as all hosts talk to a primary host [the server] and the server houses the shares [centralized]

Active Directory, which is server based, has groups.
Peer to peer does not have groups.

Guest and Everyone access is peer to peer configuration

Server/client guest account is disabled on all hosts. If restrictions are desired on a share the share is NOT shared to everyone.

Before I explain further please answer the following questions

1. are you running active directory?
2. how long have you been in IT/familar with MS server?
3. how/what did you use for the vpn access [software]?
4. why did you enable the guest account?


0

Response Number 4
Name: RSXHiTMAN
Date: September 21, 2009 at 12:38:34 Pacific
Reply:

1. no im not
2. fairly familiar
3. ICS, routing and remote access
4. makes things easier (lazy), all pcs on local network get access to the files without any specific setup...

i guess i expected vpn to login to these shares under the vpn user, not a guest


0

Response Number 5
Name: wanderer
Date: September 21, 2009 at 13:04:58 Pacific
Reply:

OK thanks.

You can't have restrictions when you have everything wide open. You mention ICS and RRAS.

Your server have two nic cards?
You configure RRAS as vpn server and to access the network?

You have two major issues, one is you can't do restrictions with guest and everyone. You would need to properly setup accounts, their passwords and permissions.

Your second issue is you desire to differenciate between vpn users accounts/access and local user accounts/access

Normally it does not matter if access via the network or vpn. Users would get the permissions they were given via either access.

If you want to differenciate between vpn users and local users you will need two accounts for each user. John Lan is local access. John VPN would be vpn access. You would put local into a localgroup and vpn users in a vpn group. This would give you the ability to adjust rights assignments via the two groups like localgroup gets full access and vpngroup only gets readonly.

You would remove everyone from the share(s). You would assign the two groups setting their security access levels accordingly.


0

Related Posts

See More



Response Number 6
Name: ace_omega
Date: September 21, 2009 at 13:09:22 Pacific
Reply:

If you turn off all of Windows Security and wonder why you can't secure then this is a nobrainer. I would suggest setting up a VPN user or group then remove the "everyone" from you share and only add the administrator, local users and the VPN. Then with the VPN you can set it to be readonly. It is not that hard to do.


0

Sponsored Link
Ads by Google
Reply to Message Icon





Use following form to reply to current message:

Login or Register to Reply
LoginRegister


Sponsored links

Ads by Google


Results for: VPN users are logged in as GUEST for fileshar

Which users are in logged in? www.computing.net/answers/windows-2003/which-users-are-in-logged-in/5801.html

Logging in as application www.computing.net/answers/windows-2003/logging-in-as-application/8294.html

XP Users Cannot Log in with Roaming Profile www.computing.net/answers/windows-2003/xp-users-cannot-log-in-with-roaming-profile/9236.html