cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
0
Helpful
1
Replies

VPN without split tunneling

hseth
Level 1
Level 1

How good is VPN securing the client machine itself. I am aware that VPN can very well protect the data from client to the gateway but if it's implemented without the split tunelling, the client is only suppose to talk to the VPN gateway but does it protect the machine itself? Can someone else other the gateway talk or see the client machine?

Thanks.

1 Reply 1

wisfaque
Level 1
Level 1

HI there

When a macine is VPNed in to a Headend device or a VPN gateway without split tunneling, the client machine is only visible to the internal lan to which the client os connected.

Anyone else from outside cannot peep into the machine.When you do traceroute to the VPN gateway IP without being VPNed in you would see many hops. But when you are VPNed in you would see only one hop.

Enabling Split tunneling does modify the routes on the machine. So whenever it has to go to the Local networj you are trying to reach it would go throught the VPN getaway othetwise would go through the nomal default gateway (for normal internet traffic). This allows the machine to be visible to the internet if it is not behind a firewall or a NAT/PAT deivce.

In case if you want to access the ionternet by sending all traffic to the VPN gateway and the gateway taking care of the rest of the routing to the internet, it is possibel if you have the VPN gateway or headend as a router or a conc and not a PIX.

Hope this helps

Thanks

Wakif