Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

I need better security on RAS Dial-in access

Status
Not open for further replies.

MonocleMike

Technical User
Oct 25, 2002
41
FR
I have a small network based on W2K Server SP3 acting as
DC in Active Directory and only 2 of the users (Mike &
Pete) have Dial-in permission. These users are also
restricted to logging in on their own machine - Mike on
Laptop1 and Pete on Laptop2. The machine restriction
works correctly when logging in on the network or doing a
full domain login using Dial-Up Networking BUT.... if they
log in to their laptop as a local user and then do a
dialup RAS session with their domain name and password
then it DOES NOT check their machine. THE DC hosts the
RRAS service and is declared to Active Directory and
appears to be using it because it correctly prevents users
other than Mike or Pete dialling in and requires the
correct domain password.
Any ideas how I can close this loophole?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top