logo       

newbie needs routing explaination: msg#00499

network.openvpn.user

Subject: newbie needs routing explaination

Hi All,

I am confused. :-[

Background:

I have a customer who needs to hook his laptop into one of
his client's networks when he is visiting that client. His
client is several hundred miles away from my customer's
facility.

Since my customer needs access to a large database (not
SQL) at his own facility, Real VNC seems to be the best method
of hooking my customer into his own database when he is at
his client's site. Real VNC would be remote controlling
my customer's computer in his office. (The laptop is to
stay at the client's facility in a locked room that my
customer rents from his client. Well, most of the time anyway.)

Since he also needs to print from the database to his client's
network printer, Open VPN seems to be the best method of opening
a tunnel between the two computers.


Problem:

Here is where my understanding of the process falls apart.
Once the tunnel is established between the two computer, I
am presuming that the two networks act as if they are hooked
directly together with an Ethernet cable between the two hubs.
(A really SLOW Ethernet cable.)

This presents a big security problem for me. It seems that
all someone at my customer's client location would have to
do to have access to everything on my customer's home site
would be to point his default route or add a route to my
customer's laptop when my customer was visiting.

Is there a way to restrict what traffic gets routed through
the tunnel? I want:

1) only the laptop to be able to send data
through the tunnel to my customer's network

2) to route LPR print jobs from my customer's
home office to the client's network LPD printer


Many thanks,
--Tony
aewell@xxxxxxxx







-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - digital self defense, top technical experts, no vendor pitches, unmatched networking opportunities. Visit www.blackhat.com


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise