Mark Minasi's Reader Forum
Mark Minasi's Reader Forum
Home | Profile | Register | Active Topics | Active Polls | Members | Search | FAQ | Minasi Forum RSS Feed
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 HALP! Questions on Windows and Windows Server
 Group Policies
 How Can I Block VPN Through GPO?
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

Keslaa
Welcome Newcomer

10 Posts
Status: offline

Posted - 03/05/2012 :  11:53:04 AM  Show Profile  Reply with Quote
We have a corporate directive to eliminate VPN by the end of the year. Concurrently, we are rolling Windows 7 to all external users. We are looking for a way to block the users from trying to connect over VPN. What I have found is to disable the Remote Access Connection Manager service. Does anyone have another suggestion that we can try? Thank you

wkasdo
Administrator

Netherlands
7405 Posts
Status: offline

Posted - 03/05/2012 :  3:53:40 PM  Show Profile  Click to see wkasdo's MSN Messenger address  Reply with Quote
Purely out of curiosity: why don't you decommission the VPN server(s) instead?

Make it as simple as you can, but not simpler -- Albert Einstein
Go to Top of Page

winoutreach5
Welcome Newcomer

USA
11 Posts
Status: offline

Posted - 03/06/2012 :  12:44:14 PM  Show Profile  Visit winoutreach5's Homepage  Reply with Quote
You could utilize group policy (http://technet.microsoft.com/en-us/library/ff602918) to implement a rule specific to the Windows 7 firewall which prohibits VPN traffic. Windows Firewall with Advanced Security Deployment Guide (http://technet.microsoft.com/en-us/library/deploy_ipsec) is a great TechNet article that can help you understand the steps necessary to accomplish the desired task. For specific ports to block traffic please refer to the TechNet library article VPN and Remote Access Connections Fail. (http://technet.microsoft.com/en-us/library/cc776171)

Another helpful resource for group policy is the TechNet library article Group Policy Planning and Deployment Guide. (http://technet.microsoft.com/en-us/library/cc754948)

Jessica
Windows Outreach Team -- IT Pro
Springboard Series on TechNet

Edited by - winoutreach5 on 03/06/2012 4:05:03 PM
Go to Top of Page

wobble_wobble
Honorable But Hopeless Addict

Ireland
4517 Posts
Status: offline

Posted - 03/06/2012 :  1:35:47 PM  Show Profile  Visit wobble_wobble's Homepage  Look at the Skype address for wobble_wobble  Reply with Quote
Jessica,

Welcome to the Forum.

May I ask you to identify yourself.
Your profile is sparse and these posts seems to indicate that you may be legit or somewhat suspect.

http://www.techspot.com/vb/topic161977.html
http://forums.majorgeeks.com/showthread.php?t=241454

Joe

After everything that has happened during the month of Jan 07, I do believe that pigs fly backwards!

http://whatismyv6.com/
Go to Top of Page

winoutreach5
Welcome Newcomer

USA
11 Posts
Status: offline

Posted - 03/06/2012 :  3:33:33 PM  Show Profile  Visit winoutreach5's Homepage  Reply with Quote
Joe, please allow me to introduce myself, my name is Jessica, and I work with the Windows Outreach Team for IT Professionals. We are not associated with the Windows Outreach Team. Our goal is to answer questions and provide sought after resources for the Windows client on communities across the web and, where appropriate, to help make people aware of the free tools and resources on TechNet which help to address their situation or issue.

We work in conjunction with the Springboard Series on TechNet (http://technet.microsoft.com/en-us/gg426312.aspx), a great resource for IT pros to explore the features of Windows and educate themselves on piloting, deploying, and managing Windows. Please feel free to email me directly if you have any questions about myself or the Windows Outreach Team -- IT Pro.

Jessica
Windows Outreach Team -- IT Pro
Springboard Series on TechNet

Edited by - winoutreach5 on 03/06/2012 4:05:18 PM
Go to Top of Page

wobble_wobble
Honorable But Hopeless Addict

Ireland
4517 Posts
Status: offline

Posted - 03/06/2012 :  4:36:42 PM  Show Profile  Visit wobble_wobble's Homepage  Look at the Skype address for wobble_wobble  Reply with Quote
Nope, adding more characters to your title don't make it any better.

Personally back in the early 2000's I bought a Doctorate in Doollogy, so you can call me Sir.

Maybe you can contact one of the many Microsoft employees who post here. In which case I'll apologise.


Joe

After everything that has happened during the month of Jan 07, I do believe that pigs fly backwards!

http://whatismyv6.com/
Go to Top of Page

JSCLMEDAVE
Administrator

USA
6116 Posts
Status: offline

Posted - 03/06/2012 :  4:52:47 PM  Show Profile  Visit JSCLMEDAVE's Homepage  Click to see JSCLMEDAVE's MSN Messenger address  Reply with Quote
Hello Jessica, and as well Welcome to the Forum.

When you signed up there was this notice which really alleviates a lot of issues here.

Again welcome to the forum.


If you agree to the terms and conditions stated below, press the "Agree" button. Otherwise, press "Cancel".

Personal note and request from your host, Mark Minasi: Please read and respect the first two sentences in the next paragraph. Thanks!

In order to use these forums, we require users to provide a first name, last name, country of origin, username, password and e-mail address. We ask the name and country merely to help build a community and promote civil discourse -- see our sticky note ( CLICK HERE ) in the Miscellany (Technical) section for more information if that's not clear.

Tim-

“This too shall pass"
Go to Top of Page

Anthony_Mann
Welcome Newcomer

USA
2 Posts
Status: offline

Posted - 03/07/2012 :  1:55:19 PM  Show Profile  Visit Anthony_Mann's Homepage  Reply with Quote
Hello JSCLMEDAVE and wobble_wobble,

I manage the IT Pro Outreach team for Windows client. Jessica and some others that all post under the "Windows Outreach Team - IT Pro" signature are part of our team that is responsible for responding to certain types of posts to help solve technical problems experienced by IT Pros relating to the Windows desktop. They also let posters know about specific resources that exist on the Microsoft site, primarily the Springboard site on TechNet. These resources are only mentioned when they directly relate to a specific problem or issue being discussed.

By the way, we report to Stephen Rose who is the IT Pro Community Manager for the Windows Commercial group at Microsoft. If there is anything else you need for us to verify authenticity or if you want to contact Stephen directly, please let me know. Also, if there is a better way for the team to introduce or authenticate themselves, either online or offline, please let me know.

Sincerely,

-Tony Mann

Web Forum IT Pro Audience Manager | Microsoft Windows Client Audience Marketing
Go to Top of Page

wobble_wobble
Honorable But Hopeless Addict

Ireland
4517 Posts
Status: offline

Posted - 03/07/2012 :  4:13:27 PM  Show Profile  Visit wobble_wobble's Homepage  Look at the Skype address for wobble_wobble  Reply with Quote
Mr Mann,

Thanks for that, but you will have to excuse my scepticism about the post for several reasons.
1. Not a lot on the various organisation names you all use.
2. Not a lot of information on the various organisations that you claim, that show you all in a good light.
3. Not very informative profiles.
4. Surely if you you work for MS your signature would be MSFT, MS CSG or similar.
5. The frauds that are going on, with calls to people, offering to fix their computers as they work for Microsoft.
6. Most companies will offer help, on their products, on their forums. Why? Well one reason is that admins here could technically edit your comments to put Microsoft in a bad light. I'm sure they would not like that....
7. I'm just naturally suspicious.
8. I'm just naturally suspicious.
9. I'm just naturally suspicious.

Joe

After everything that has happened during the month of Jan 07, I do believe that pigs fly backwards!

http://whatismyv6.com/
Go to Top of Page

wkasdo
Administrator

Netherlands
7405 Posts
Status: offline

Posted - 03/07/2012 :  4:46:02 PM  Show Profile  Click to see wkasdo's MSN Messenger address  Reply with Quote
Joe, FYI: these names check out in the GAL, except for Jessica which is too generic.

@ Jessica and Tony: we are fighting a continuous war against sp*m and fraud here, and so far we keep on top of it thanks to our community paranoia. Nothing personal!

Make it as simple as you can, but not simpler -- Albert Einstein
Go to Top of Page

wobble_wobble
Honorable But Hopeless Addict

Ireland
4517 Posts
Status: offline

Posted - 03/07/2012 :  4:53:47 PM  Show Profile  Visit wobble_wobble's Homepage  Look at the Skype address for wobble_wobble  Reply with Quote
Willem,

Yup - don't have a GAL, have GoogleBing

Yup.






Joe

After everything that has happened during the month of Jan 07, I do believe that pigs fly backwards!

http://whatismyv6.com/

Edited by - wobble_wobble on 03/07/2012 4:55:25 PM
Go to Top of Page

wkasdo
Administrator

Netherlands
7405 Posts
Status: offline

Posted - 03/08/2012 :  05:41:41 AM  Show Profile  Click to see wkasdo's MSN Messenger address  Reply with Quote
I'm locking this topic until I get confirmation that this is legit. Sorry for the hassle.

Make it as simple as you can, but not simpler -- Albert Einstein
Go to Top of Page

wkasdo
Administrator

Netherlands
7405 Posts
Status: offline

Posted - 03/09/2012 :  02:46:30 AM  Show Profile  Click to see wkasdo's MSN Messenger address  Reply with Quote
unlocked

Make it as simple as you can, but not simpler -- Albert Einstein
Go to Top of Page

JamesNT
Moderator

USA
3150 Posts
Status: offline

Posted - 03/09/2012 :  06:39:36 AM  Show Profile  Visit JamesNT's Homepage  Click to see JamesNT's MSN Messenger address  Reply with Quote
I think the idea of actual MS participants helping out on the forum set off a few "too good to be true" alarms.

JamesNT

James Summerlin
www.jamessummerlin.com
Go to Top of Page

Anthony_Mann
Welcome Newcomer

USA
2 Posts
Status: offline

Posted - 03/12/2012 :  7:43:23 PM  Show Profile  Visit Anthony_Mann's Homepage  Reply with Quote
quote:
Originally posted by JamesNT

I think the idea of actual MS participants helping out on the forum set off a few "too good to be true" alarms.

JamesNT



Hi JamesNT,

Too funny. If you ever have any questions about the team or any of its individual members, please private message or email me.

Thanks

-Tony

Web Forum IT Pro Audience Manager | Microsoft Windows Client Audience Marketing
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Mark Minasi's Reader Forum © 2002-2011 Mark Minasi Go To Top Of Page
This page was generated in 0.2 seconds. Snitz Forums 2000