Switch to full style
Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems
Post a reply

Found a huge security hole. How do we plug it?

Feb 23 07 10:28 am

We are using the latest version of wingate (6.2.0 build 1121)and are using KAV and Puresight (latest versions). What we have found just today is that if clients use automatic IP address settings, (Wingate DHCP) then everything works like it should, but if clients sets a manual IP address then they have full and open access to the internet, and do not show up anywhere in Gatekeeper or its logs! even in its Client activity screen. The client is just invisible!

Needless to say, this is not acceptable. What is wrong and what can we do about it?

Brian

Feb 23 07 11:58 am

Do these clients gain access to the internet directly through a router - effectively bypassing WG? Or do they still have Gateway pointing to WG server?

Gateway still the same

Feb 23 07 12:02 pm

They still have the gateway still pointing to the WG server.

Brian

PS to that...

Feb 23 07 12:03 pm

BTW, they have to go through the WG machine, there is no physical access to the internet otherwise.

Problem fixed

Feb 23 07 12:09 pm

We upgraded to build 1131 and that seems to have fixed the problem.

Brian

Re: Problem fixed

Feb 23 07 12:59 pm

bhollna92000 wrote:We upgraded to build 1131 and that seems to have fixed the problem.


Interesting - but good to know! I wonder what it was?
Post a reply