LucyHeart Lv3Posted 2022-Nov-21 11:12
  
Your status is very hard.
grayice499 Lv2Posted 2022-Nov-21 11:33
  
Make a policy that NON AD Group will be block.
kmrnliaqat Lv3Posted 2022-Nov-21 12:28
  
Review your polices.
Imran Tahir Lv4Posted 2022-Nov-21 12:50
  
Recheck the policy
sanjigerma Posted 2022-Nov-21 14:05
  
Please rescan your policy, maybe there were some misconfig
jetjetd Lv5Posted 2022-Nov-21 23:40
  
You need to double check your VPN policy.
arjay Lv3Posted 2022-Nov-22 12:09
  
Please double check your policies
Farina Ahmed Lv5Posted 2022-Nov-22 13:57
  
Very nice topic and very good question, because no non ad user have to privilege's to use the VPN tunnel as it is related to our organization security. First of all, look at your policy, it might not be working or implemented yet. Second thing, segment your network which is very necessary in this case. The guest users/non ad users should be on different network and not on the same network so in this way that traffic can be controlled.
CTI_JianJie Lv2Posted 2022-Nov-24 15:23
  
Hi, there is only one option in the Sangfor VPN to achieve the branch user's access internet via the HQ firewall.
When the Sangfor VPN tunnel route "enabled access internet via destination route user", else it will not route other traffic to the VPN tunnel.
Please do check on the setting above, if the issue is not working as expected, we suggest sending an email to tech.support@sangfor.com for us to assist on the problem.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Faris Khan Lv2Posted 2022-Nov-24 17:18
  
Dear User,
Thank you for all your response. As we further diagnose the issue. checked the policy multiple time. there is no tunnel route in the VPN. The non authenticated user were able to use internet because in authenication sso tab advance option has a check that allow user to a have access the DNS server before authentication. that was checked when we unchecked it the issue was resolved. thank you all for the response. it help us to diagnose the issue.

Thank you

I Can Help:

Change

Moderator on This Board

1
152
3

Started Topics

Followers

Follow

1009
209
99

Started Topics

Followers

Follow

Board Leaders