Jump to content

Recommended Posts

Posted

So I thought I'd use some spare time (now things are a bit quieter) to look into

getting VPN access to school from home (initially just for me and maybe SLT at some point)

 

As we have a smoothwall I started with this https://kb.smoothwall.com/hc/en-us/articles/360012413300-Setting-up-the-Smoothwall-SSL-VPN-Window-based-Client

 

However I feel a bit out of my depth so will need to do a bit of background reading I think on certificates etc.

 

I'm just trying to get my head around how this will work / what it will look like when/if I get it working:

 

Smoothwall gives me a zip with 3 files:

client (but can I use a different client e.g. one built in to windows 10?)

.ovpn (settings file ?)

.pem (a certificate ?)

 

I use the client and enter AD user name password and boom, I'm "connected" to school ?

 

So at this point my current home network is disconnected: I can't access any devices on my home LAN ?

 

It's like I'm connected to the school LAN with a school IP, DNS etc ?

 

So if I browse on my PC to a website is it going through the vpn to school then back out to internet?

 

and can I map network drives to school server?

 

and can I use mstsc to connect to my school PC desktop ? (much safer than forwarding 3389 on firewall ?)

 

 

What about security though?

 

It looks like by default smoothwall authentication is done against our on site

Active directory. But some of the teachers passwords are not that secure and could

be brute forced easily enough.

 

How do others mitigate this when using VPN ?

 

Can I just set it up so only my username with super strong password is allowed in ?

Posted

ovpn is an open vpn settings file yes, and pem is a certificate

 

Can you use the ovpn file on another computer without the certificate?

 

I would think you could select a group in AD that was the only group to allow vpn, but can't see that in smoothwall manual, maybe you have to do another ad bind

 

Whether you can access your lan/internet not via vpn depends on the vpn settings, split site, really what order/priority the routes are, see cmd line: route print

Posted

thanks,

so am I right that if a rogue actor got hold of the cert and opvn they could brute force a login?

 

and once connected to a vpn the PC at home is essentially just another PC on the school LAN (kind of connected by

a (very) long virtual ethernet cable)?

Posted

Yes, but they'd need the cert and a username/password, so it's already two factor.

 

Yes, essentially, depending on the setup. And it's tricky to have it connected from boot, so computer GPOs might not work as well.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...