Jump to content

Recommended Posts

Posted

Hi all

 

Have set up direct access on 2012, working OK.

 

My issue is, I need to restrict access to the domain while users are offsite i.e. at home.

 

So when they are in school the gpo applies and all is well. When they are at home the school gpo still applies! I thought, I could edit the DirectAccess client setting gpo to restrict their offsite connection?? I tried a test on that gpo but it did not have any effect.

 

Any ideas?

 

Thanks

Posted

Question, why do you want to do this as surely this defeats the whole point of DA?

 

Suppose a lot of it depends on what you actually mean with "Restrict Access to the Domain"?

Posted
It does sort of defeat the object. The powers that be, do not want staff accessing certain data outside of school, i.e Sims data!! Although They can email, memory stick etc...as I have told them repeatedly.., :)
Posted
I'm not sure that's possible... If they want that, my best offer would be to scrap direct access and just have them log in on to an RDP session that you can tie down.
Posted (edited)
Could you use item level targeting on the DA GPO to only apply on a particular IP range? (never actually tried this myself)

Cant see this working - the DA client will have an IPv6 address assigned to it (Either pure IPv6 if the OP has it setup, or via 6to4/Teredo)

 

Having said that, you could just add a HOSTS file hack on the DA server :

 

127.0.0.1  sims-server  sims-server.domain.com

Edited by Gatt

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...