Forum Discussion
Network Access - Block Virtual machine for VPN connection.
Thanks Boneyard!
Here we need to deny VM based machines.So that non vm based machines will go in the tunnel and won't be any communication to internet .
why this focus on a difference between virtual and none virtual machines?
you say something about with a virtual machine it is split tunnel, but why would that be the case?
the big-ip edge client doesn't behave differently on a virtual or non virtual machine.
- KashMay 01, 2020Altostratus
For clear understanding ,
Objective is to allow vpn users to access intranet sites only .Full tunnel enabled at APM policy.
scenario : I installed Virtualbox with win 10 OS in my laptop. Connect VPN @ vm machine .(Full tunnel enabled) .Able to access intranet sites only using VM browser .( expected result)
But using my physical laptop browser (vm is running and connected to VPN) i can able to access internet websites.Becz its not connected to VPN( expected result).
On above scenario its like a split tunnelling ( vm no access to internet websites , Laptop have access to internet websites ).
so need to block all vm based machines on posture check or is there any other possible ways ?
Note : VPN access via browser not f5 edge client and No cert .
Thank you!
- boneyardMay 01, 2020MVP
Ok, but the usual reason against split tunnel is because it is unsafe. locally traffic might get onto the internet and then also access the network behind the VPN. that is not the case with your situation. you wont be able to access the network behind the VPN from your laptop, you have to switch to your VM to do that. so that security issue is way less here.
Or is in your case you dont want people to access the internet for other reasons then security?
Will it be possible to install software on the client forcing a registry check or such?
- KashMay 01, 2020Altostratus
yes .I dont want people to access the internet .
Is there anyway to detect VM based machines on posture check and block it.
Majority all are personal laptops,what type of software to install and check ?
Many tHanks!!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com