Jump to content

Recommended Posts

Posted

I'm getting mixed messages about handling split tunneling for our AOVPN.

Currently it's working well for the majority but so many little niggles are keeping me busy. One thing I heavily suspect is an issue is the fact that all off-site traffic to Office 365 has MFA enabled in Azure. This works very well for email, however things like OneDrive and general office365 use whilst working at home connected to the VPN can be ropey.

Selective split tunneling is being used, so the only traffic that goes through our network is traffic directly aimed at it - internal drives and services only. I'm reasonably confident that if I added all the Office 365 IPs and addresses to the split tunneling setup we'd get around this - but a) that's a hell of a lot of addresses to add and b) that puts a lot more traffic through our already busy network. MS are aware of this extra load of course and have guides for enabling only certain bits of O/M365 in split tunneling but its not something I'd want to go implementing in a rush.

Does anyone else have any experience of this?

Ideal scenario of course is that everything stays as it is, only internal traffic goes via our network but 365 recognises the device as being "in school" and no longer prompts for MFA after a timeout. Wondering if maybe there's something internal we can do as MFA works via an internal NPS server.

Posted

Are you not letting all internet traffic connect direct?

MFA should only prompt once a day via conditional access. If you've got the money for Azure Active Directory Identity Protection, it will learn the usual location and device the user is using. If you have your device AAD Hybrid joined this can also be used as a Conditional Access method rather than MFA. However not all apps support this. Adobe Creative Cloud Desktop App for example.

Posted
Will take a look at that - not sure if its on our licence (A3). We have all internet traffic going directly out but just wanted to rule out the MFA as an issue - i may very well be overthinking it!
Posted
A low effort/risk and high payoff approach would be to split tunnel only teams AV traffic, this is a couple of chunky subnets but assuming you're using teams video will account for most data.
Posted
We use split tunnel here and only allow traffic through to specific severs, forcing everything else direct to the internet, we also use MFA with no problems. If using Microsoft AOVPN how do you define your split tunnel in you .xml file? eg. do you define RemoteAddressRanges, Routes (Disabling the class based default routes), is your internal school network on a different subnet to end users (e.g. if a home users ip address is in the range 192.168.0.0/24, are your internal servers on a different subnet, which can cause intermittant problems)? Have you got any group policy settings in to force certain site/people through your internal webproxy that could be affecting things?
Posted
Gonna throw something in here, obviously if a proxy is set on your browsers the split tunnel will be worth less as internet traffic will be coming back via your proxy server.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...