Jump to content

Recommended Posts

Posted

First of thanks for taking the time to read this and i need to apologise for my ignorance when it comes to offsite domain machines and vpn connections.

 

We are currently using windows 7 and are actively moving to windows 10. We use a Sophos XG as a firewall and our admin team are the only members that have remote access via VPN. This is via a client that they run on their home unrestricted PCs. These are used to RDP into our server to perform out of hours maintenance etc. We have policies in please to restrict it's use.

 

Our SLT team "needs" new laptops, but now i have to think of GDPR and the responsibility we have to make sure the provided and school owned Laptops are secure, locked down and used for purpose. (TPM, bitlocker restricted and authorised use)

 

In a ideal scenario i'd like the laptop to behave just like onsite machines, with the GPOs configured to allow them to connect to their own wifi and printers.

 

Is there a way that Win10 can connect to a onsite domain automatically from a logon AUP screen once connected to wifi ?

 

After that i guess it would just be like an onsite laptop.

 

Thanks for any info.

 

cheers

Posted
"DirectAccess" is basically a gpo controlled automatic VPN that works with server 2012+ and windows 8.1 and 10. No user intervention needed, pretty easy to setup.
Posted
"DirectAccess" is basically a gpo controlled automatic VPN that works with server 2012+ and windows 8.1 and 10. No user intervention needed, pretty easy to setup.

 

I have set-up Microsoft DirectAccess previously too, it's quite something! Allows WSUS to push updates to them off-site, GPOs apply, remote desktop and remote assistance work well too!

 

Bare in mind however that it uses IPv6 and/or DNS/NAT 6to4 as a proxy through the DirectAccess server. Some applications wouldn't run properly over this when I played with it (such as the Impero Remote Control to a client. Lightspeed internet filter client also had a few issues initially however I think those were sorted in the end), as they required native IPv6 support.

 

This was 3 odd years ago however so it might have changed, but thought it best to let you know. Might be worth checking first! :)

 

----------------------------------------

 

Actually, you might want to check this first! Richard Hicks blog was immensely helpful when I went through the set-up process, but it looks like DirectAccess may not be here for the long term!

 

https://directaccess.richardhicks.com/2017/07/24/always-on-vpn-and-the-future-of-microsoft-directaccess/

Posted

We've implemented DirectAccess too, and have looked at AlwaysOn. We don't have a need to move to AlwaysOn at the moment, but can't see a reason we wouldn't implement that now should we be starting again.

 

Koryo is correct about Impero. It will connect to the server if you have a DNS A record in place for the Impero Server, but thumbnails and most other functionality won't operate as they're peer to peer and / or over IPv4.

 

One thing to note is that as the Impero Client is connected to the Impero Server, it does not log activity locally for upload later (it would if the client couldn't find the server). As the connection to upload this is over IPv4, nor does it upload the data.

The way to stop this is to block the Impero connection port (support will be able to assist with details / PM me) on the DA server firewall, which means when connected via DA, Impero doesn't connect at all. As it knows it isn't connected, the data will cache locally for upload when the device returns to the network.

 

The other easy work around for some applications which simply need to resolve a host, where the host only has IPv4 is create an A record in DNS to forward the name to IPv4, removing the need to run the thing you're resolving on IPv6.

 

Mic

  • 3 weeks later...
Posted
AlwaysOn VPN ftw. Just testing it for a handful of clients and is the way we will be going. Finally a reason to jump to win 10 lol

 

I'm just looking at setting this up at my place now. Did you have any problems with getting it installed and working?

 

Thanks,

  • Thanks 1
Posted
I'm just looking at setting this up at my place now. Did you have any problems with getting it installed and working?

 

Thanks,

Pretty easy tbh. There are a few guides out there. Easier that DA but you do need win 10 and a PKI
Posted
Yeah, I'm just following the guides on Microsoft Docs at the minute, seems easy enough. Hopefully will get it finished by the end of the week. Is it really seamless when users go off site?
Posted

Yeh seamless. Configured ours as split tunnel as just couldn't get forcetunnel to route out to the internet. Proxy is set by PAC file so if reachable internet traffic goes through our smoothwall . Had to explain this to a teacher testing it for us just in case of any "personal" browsing

 

Also make sure you set the VPN connection to register with DNS

 

I have our powers hell running everyday to put the VPN back in everyday in case anybody deletes it. Done via sccm package

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...