access by IP-addresses

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

access by IP-addresses

Postby bigkush » May 24 06 2:50 am

WinGate 6.1.2 (build 1094)
If we are having access from outside to a pc in the office through remote desktop connection (a certain port is opened), can that access be limited to certain (outside) IP-addresses only and how shoud we do it?
Thank you!
Sergiy Kushnir,
Windows 2003 + WinGate + WinGate VPN + MDeamon
bigkush
 
Posts: 10
Joined: Mar 16 06 10:06 am
Location: Kyiv, UKRAINE

Re: access by IP-addresses

Postby Nev » May 24 06 10:24 pm

bigkush wrote:WinGate 6.1.2 (build 1094)
If we are having access from outside to a pc in the office through remote desktop connection (a certain port is opened), can that access be limited to certain (outside) IP-addresses only and how shoud we do it?
Thank you!


Hi Sergiy,

Try this post here for a method using a non standard port of your choice which is safer yet redirected to the client by Wingate's ENS in a port forward.
--
Nev.
Nev
WinGate Guru
 
Posts: 861
Joined: Sep 22 03 11:35 pm
Location: Mudgee ~ NSW ~ Australia

restricting access to specific static IPs

Postby bigkush » Jun 14 06 12:56 am

We already have a redirect from a non-standard port to our local computer through TCP Mapping Service. What we need to know is how to allow access from specific outside IP-addresses ONLY. So, for example, I can connect to my local computer inside the office (behind Wingate) via remote desktop connection from a pc outside the office (via internet) that has a specific static IP-address and only from that IP-address, so I can be sure no one can use remote desktop connection to my computer as a security ”hole”.

Thank you!
Sergiy Kushnir,
Windows 2003 + WinGate + WinGate VPN + MDeamon
bigkush
 
Posts: 10
Joined: Mar 16 06 10:06 am
Location: Kyiv, UKRAINE

Re: restricting access to specific static IPs

Postby Nev » Jun 14 06 11:53 am

bigkush wrote:We already have a redirect from a non-standard port to our local computer through TCP Mapping Service. What we need to know is how to allow access from specific outside IP-addresses ONLY. So, for example, I can connect to my local computer inside the office (behind Wingate) via remote desktop connection from a pc outside the office (via internet) that has a specific static IP-address and only from that IP-address, so I can be sure no one can use remote desktop connection to my computer as a security ”hole”.

Thank you!


Ah, source routing, cannot be done with this version of Wingate.
--
Nev.
Nev
WinGate Guru
 
Posts: 861
Joined: Sep 22 03 11:35 pm
Location: Mudgee ~ NSW ~ Australia

Postby ChrisH » Jun 15 06 1:35 am

Instead of using the IP address to verify who you are, what about remotely authenticating with WG using the QbikAuth tool then setting up a policy with this TCP mapping service that only allows you as the user and you must be authenticated? This method does mean binding the Remote Control service to your external NIC.
Chris H.
ChrisH
WinGate Master
 
Posts: 388
Joined: Sep 13 03 1:38 am
Location: Canada

Postby Pascal » Jun 15 06 8:45 am

Chris has got the right idea there. You could extend that to use policies to restrict the IP addresses allowed to connect to that TCP mapping Service.

However, have you considered using the VPN to establish a network link between your home / office networks? Then you authenticate the VPN link, it's encrypted and you can access machines as if you were on the local network.

I do that from home when I need to make quick changes, etc.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

not assumed users are 'Administrators'!

Postby bigkush » Aug 23 06 9:17 pm

I am using assumed users.
I have 'User must be assumed' in System Polocy. In assumed users every user is assumed by IP-address (we have network with static local IP-addresses only). But recently I found out that if somebody tries to get to Internet from a local PC with IP-address that is not stated in assumed users, this computer does get access with no problem and it becomes assumed Administrator.
How can I fix that?

Now every computer with proxy configured in the browser settings has unlimited access to Internet!
Sergiy Kushnir,
Windows 2003 + WinGate + WinGate VPN + MDeamon
bigkush
 
Posts: 10
Joined: Mar 16 06 10:06 am
Location: Kyiv, UKRAINE

Postby jamesc » Aug 24 06 7:25 pm

This post may help with the port restriction:

http://forums.qbik.com/viewtopic.php?t= ... hlight=vnc


Regarding your assumed user problem: Do you have any wild cards in the assumption for the Administrator?
jamesc
Qbik Staff
 
Posts: 928
Joined: Apr 04 05 2:04 pm
Location: Auckland, New Zealand

Re: access by IP-addresses

Postby kgoodknecht » Aug 25 06 4:48 pm

bigkush wrote:WinGate 6.1.2 (build 1094)
If we are having access from outside to a pc in the office through remote desktop connection (a certain port is opened), can that access be limited to certain (outside) IP-addresses only and how shoud we do it?
Thank you!


You can enable RRAS as a router only (no NAT) and set up inbound packet filtering with TCP 3389 open only from your IP address to the external NIC.

Q254018 - How to Configure Input Filters for Services That Run Behind Network Address Translation:
http://support.microsoft.com/default.as ... us;Q254018
Best regards,

Kevin Goodknecht [Microsoft MVP]
See me in the Microsoft Public DNS newsgroups
kgoodknecht
Senior Member
 
Posts: 161
Joined: Nov 24 03 1:31 pm
Location: Wichita Falls, TX


Return to WinGate

Who is online

Users browsing this forum: No registered users and 30 guests