Maybe a bit too secure

You know I’ve always been a big advocate of finding that fine line with technology where it’s secure, but still usable. Today at the office I think we found someone crossing that line a bit. We had a client laptop in our office. They needed to use our guest network to VPN to their network, which is completely common and no big deal really. We don’t have a publicly available network in our office, you do have to call the help desk and we assign a username/password combo specific to you, so that way if someone’s using the network to do something untoward, we can track down who it was.

Like most networks like ours, we redirect your browser when you first connect to our network to do the authorization before you can go anywhere else. Well, this laptop had proxy settings in the browser. It was trying to access a public proxy server, which of course it couldn’t because it hadn’t authenticated with the network yet, but the proxy was interfering with our redirect so nothing happened. So we disabled the proxy. We got a good connection, and the VPN wouldn’t connect. Turns out that the VPN server on their network requires that all connections come through that proxy server. Not only does it not allow other connections, but it automatically disables the account of the person trying to sign in to the VPN.

Yes, it took numerous phone calls, and our network engineer to talk to their network engineer before we figured out how to work around this. (Disable the proxy, authenticate with our network, re-enable the proxy, THEN connect the VPN)

Seems to me that the usability factor had been lost in this equation. But maybe that’s just me.

Tags: VPN, proxy

Similar Posts

  • Swatting flies

    I read with interest the post by Security Monkey today about swatting flies, not because I don’t agree with him about his point, but his example really brought to mind another of my pet peeves about working in IT generally, but Help Desk specifically. Let’s start with his example: Your help desk reports to you…

  • Bad IT Day

    What’s a bad IT day? How about a day where you have more servers being wonky than you have server admins available to deal with them? We had that one afternoon this week. A voice mail server off-line, a Blackberry Server running at about 30-40 minute delay, and a whole bunch of users have some…

  • Happy Hour

    On Friday I went out after work with some of coworkers. It was one of our office assistant’s last day working for the Firm, and she was someone I’ve always gotten along with pretty well. Since she took it upon herself to specifically mention to me where they were going and since I really had…

  • Speaking of big stinks

    Speaking of big stinks, I just had to replace a monitor upstairs. I knew as soon as I hit that hallway that it had shorted, the odor was a definite give away. Luckily we had an extra sitting at an empty cubicle, so I didn’t have to run out and buy one on the spot….

  • | |

    Linked – Why clicking on pop-up tech support ad could cost you

    One of the best things to protect yourself, Jutras says, is to take your computer offline and then contact the actual provider. Also, do not click on links or documents you don’t recognize. “A legitimate company won’t call you and ask for money,” says Jutras. This is really becoming a thing, so let’s talk about…

  • Where was this 2 years ago?

    When I was switching jobs, leaving a place where I was the only IT person and trying to document everything I did and leave instructions about how to do it, I seriously could have used this Lifehack article about How to Give Instructions. I can definitely attest to how difficult it is to put yourself…

One Comment

  1. No, I think you have a point there. Some VPN clients are too obessessed about security it makes it impossible for guests to logon. I guess you can draw a reference in today’s world where airport security is a major issue. Some VPN clients just want to have good safety measures to prevent attacks by hackers.

    Nationwide VPN

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)