• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

VPN and IP addresses

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    VPN and IP addresses

    Hi,

    I'm not a network guy, could someone that is offer a little advice please?

    My current client has a software system hosted on the cloud. The system is locked down to only allow access from certain IP address ranges - namely their office.

    They also operate a VPN for remote working. I had a reasonable expectation that things could be configured so that I could connect to the VPN from home, and have my traffic routed through their office location, thereby gaining access to the cloud-based system.

    They outsource their IT support and the guy I'm talking to says that's impossible. That feels like the wrong answer to me, and although I'm prepared to be wrong, I'm wondering if this is perhaps just not his area of expertise.

    Can anyone tell me if I'm asking for the impossible, and if not, maybe help me word a request that will move things forward?

    Thanks in advance!

    #2
    It possible, however most VPN's will place you on a DMZ with restricted access to the host network, the subnet approved for access to the cloud will be different to the subnet allocated to users on the VPN, you can ask to add the VPN subnet to the whitelist of approved IP's
    Originally posted by Stevie Wonder Boy
    I can't see any way to do it can you please advise?

    I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

    Comment


      #3
      I've done exactly that before. So certainly is possible.

      If you connect to the VPN and tracert somewhere on the internet does it go through the office LAN? If not it may be that you need to set up a static route at your end.
      Will work inside IR35. Or for food.

      Comment


        #4
        Thanks for replies. So if I do a traceroute with and without the VPN it's virtually identical, so I'm guessing the answer is no, it's not going via the LAN yet.

        So...

        Do I need to do something like this (I'm on a mac) and route traffic to the end destination via some IP address at the office?

        https://meinit.nl/add-permanent-static-route-mac-os-x

        Comment


          #5
          Yep. If there's a NAT internet router that you can get to via the VPN then that should work.
          Will work inside IR35. Or for food.

          Comment


            #6
            As Simon says, alternatively you could VPN in and RDP to a machine on that VLAN that is allowed, or just fudge teamviewer on a machine in the office

            Comment


              #7
              Thanks - the Teamviewer fudge is currently in place, but I'm going to need a more robust solution as we roll out to several remote users shortly, so will pursue the rest of the suggestions given. Thanks for all the free advice, it's appreciated.

              Comment


                #8
                Originally posted by meanttobeworking View Post
                Hi,

                I'm not a network guy

                This is something I have been thinking about more and more. I have picked up enough over the years to hold my own with a medium networking guy, but once the pro comes out I am floored.

                I have thought of taking a CCNA or something similar even if it's just to be able to articulate better with the arrogant networking pro.

                Comment


                  #9
                  Originally posted by meanttobeworking View Post
                  Thanks - the Teamviewer fudge is currently in place, but I'm going to need a more robust solution as we roll out to several remote users shortly, so will pursue the rest of the suggestions given. Thanks for all the free advice, it's appreciated.
                  This is where Citrix comes into its own, thin client into the office and then from there its just like being on the network.

                  A quick and dirty solution would be a jump box, those on the VPN can access the jump box and only the jump box which can then connect anywhere it needs to. A terminal service licence would be needed to avoid the maximum two at a time issue, but even basic networking knowledge could set something up where the VPN and internal LAN are still isolated
                  Originally posted by Stevie Wonder Boy
                  I can't see any way to do it can you please advise?

                  I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

                  Comment


                    #10
                    Originally posted by SimonMac View Post
                    This is where Citrix comes into its own, thin client into the office and then from there its just like being on the network.

                    A quick and dirty solution would be a jump box, those on the VPN can access the jump box and only the jump box which can then connect anywhere it needs to. A terminal service licence would be needed to avoid the maximum two at a time issue, but even basic networking knowledge could set something up where the VPN and internal LAN are still isolated
                    Thanks for your reply, sorry to have missed it until now.

                    In the end, someone more senior got involved and "activated u-turning on the firewall", which seemed to do the trick, whatever that is!

                    Comment

                    Working...
                    X