Hi, I want to enable my domain users to add static route to their computers but I don’t know which GPO can help me on this.
Can some one help me on this?
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Enable domain users to add static route
Home » Forums » Admin IT Lounge » Admin IT Lounge – Miscellaneous » Enable domain users to add static route
- This topic has 11 replies, 3 voices, and was last updated 11 years, 7 months ago.
AuthorTopicWSmahmood_teh
AskWoody LoungerNovember 9, 2013 at 7:05 am #491884Viewing 7 reply threadsAuthorReplies-
WSTinto Tech
AskWoody LoungerNovember 9, 2013 at 7:56 am #1421957You can use your Logon scripts.
If you want specific users to have certain static routes configured, you could call a batch or powershell script from within the logon scripts. However, I think this would need local admin privileges for the user account.
If you want specific machines to have static routes, you could configure that on the computer account logon rather than the user account. This would use the System account and not require elevated user permissions.
I general, allowing users to add or modify static routes is a potentially dangerous thing to do for the security and health of your network: if you need static routes, I think it would be preferrable to configure it on the computer account rather than for the user.
-
Paul T
AskWoody MVP -
WSmahmood_teh
AskWoody LoungerNovember 10, 2013 at 7:46 am #1422072Paul T & Tinto Tech: Thanks for reply,
Actually I have a VPN dialler that as soon as user log-ins into his/her machine dial a VPN connection for internet access.
I want when VPN connection established, a static route be added to users machine for routing all of it’s internet traffic through this tunnel.
Every this goes find but adding this static route because the user does not have such a permission.
I don’t know which GPO rule can suits my need. -
WSTinto Tech
AskWoody LoungerNovember 10, 2013 at 2:17 pm #1422144Actually I have a VPN dialler that as soon as user log-ins into his/her machine dial a VPN connection for internet access.
You have a somewhat unusual configuration. No doubt there is a very valid reason for this configuration, but it is difficult in this circumstance to answer without understanding the reasons reasons why you need a VPN for internet access for all users.
You do not describe the VPN dialler, but often these tools will have settings to route internet traffic automatically.
Alternatively you could deploy an on-site proxy server which manages all internet traffic: it could even direct this traffic over a VPN if needed. This provides a single point for configuration as Paul T suggested.
Failing that, setting a per computer static route in the AD Computer logon script should meet the requirement, but that may have unwanted implications for the reasons why you need VPN access for internet traffic.
-
Paul T
AskWoody MVPNovember 11, 2013 at 1:07 am #1422213It is also difficult to set routes for internet access because the IP address could be almost anything and you effectively have to set a default route to the internet, with specific routes for local traffic. To get around that problem you set the browser to use a proxy, which should be possible with the VPN software.
cheers, Paul
WSmahmood_teh
AskWoody LoungerNovember 11, 2013 at 2:07 am #1422221Honestly, my customer wants his employees only use VPN connection for accessing to the internet. My dialler can handle everything including finding the assigned IP address by VPN server and adding static route.
But my difficulties is on a windows domain environment. For adding static route to clients, this dailler needs permissions except administrator ones. For tracking user’s internet usage we need them to login by dailer with their domain usernames and for that their account must have required privileges for adding static route.Paul T
AskWoody MVP-
WSmahmood_teh
AskWoody Lounger
WSTinto Tech
AskWoody LoungerNovember 11, 2013 at 3:54 pm #1422369I think there is more to your requirement than in your original request and it sounds a bit complicated the way you intend to do it. As Paut T suggested a VPN would not know how to route outgoing connections to hosts over the internet.
If your customer requires to track, monitor, or control his user’s internet access, then a VPN is not the way to do it. A VPN will provide secure point to point communications. This can be made anonymous at the far end and is sometimes used to transit national boundaries where restrictions would otherwise prohibit. But a VPN does not in itself control, log or otherwise monitor traffic. To do that you need a Proxy. In fact, reading between the lines, I think your dialer is in part a Proxy service, but not one that we might describe as normal.
I recommend that you deploy a full proxy server. Have your users authenticate against that Proxy Server using Active Directory – no additional authentication, just the single sign on in AD. The proxy server can be configured to log, monitor or control users actions in pretty much any way you wish. It can then also dial out the http requests over a VPN service if you need that secure point to point or anonymous connection.
The VPN forms part of the network connection operating at Layer 3 while the Proxy implements your control, monitoring and logging at the transport Layer 4.
-
WSmahmood_teh
AskWoody LoungerNovember 12, 2013 at 3:25 am #1422407Well, all you say is absolutely right and I agree with that.
My dialler can handle almost every thing and I only have this problem on windows domain environment.
This dialler after establishing VPN connection to the VPN server must have enough privileges to add static route on client machine.
This dialler uses user’s windows credencial as user-name and password for establishing VPN connection.
Unfortunately I can not change network topology and this decision has been taken based on customer’s network data-flow.
Attached file may be helpful.
35449-Screenshot-from-2013-11-12-113709
Paul T
AskWoody MVPViewing 7 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Very Quarrelsome Taskbar!
by
CWBillow
5 minutes ago -
Move OneNote Notebook OFF OneDrive and make it local
by
CWBillow
2 hours, 8 minutes ago -
Microsoft 365 to block file access via legacy auth protocols by default
by
Alex5723
3 hours, 27 minutes ago -
Is your battery draining?
by
Susan Bradley
2 hours, 52 minutes ago -
The 16-billion-record data breach that no one’s ever heard of
by
Alex5723
5 hours, 24 minutes ago -
Weasel Words Rule Too Many Data Breach Notifications
by
Nibbled To Death By Ducks
6 hours ago -
Windows Command Prompt and Powershell will not open as Administrator
by
Gordski
9 hours, 15 minutes ago -
Intel Management Engine (Intel ME) Security Issue
by
PL1
12 hours, 11 minutes ago -
Old Geek Forced to Update. Buy a Win 11 PC? Yikes! How do I cope?
by
RonE22
2 hours, 29 minutes ago -
National scam day
by
Susan Bradley
5 hours, 25 minutes ago -
macOS Tahoe 26 the end of the road for Intel Macs, OCLP, Hackintosh
by
Alex5723
2 hours, 40 minutes ago -
Cyberattack on some Washington Post journalists’ email accounts
by
Bob99
1 day, 7 hours ago -
Tools to support internet discussions
by
Kathy Stevens
1 day, 13 hours ago -
How get Group Policy to allow specific Driver to download?
by
Tex265
22 hours, 9 minutes ago -
AI is good sometimes
by
Susan Bradley
1 day, 14 hours ago -
Mozilla quietly tests Perplexity AI as a New Firefox Search Option
by
Alex5723
1 day, 4 hours ago -
Perplexity Pro free for 12 mos for Samsung Galaxy phones
by
Patricia Grace
2 days, 14 hours ago -
June KB5060842 update broke DHCP server service
by
Alex5723
2 days, 13 hours ago -
AMD Ryzen™ Chipset Driver Release Notes 7.06.02.123
by
Alex5723
2 days, 17 hours ago -
Excessive security alerts
by
WSSebastian42
1 day, 7 hours ago -
* CrystalDiskMark may shorten SSD/USB Memory life
by
Alex5723
3 days, 2 hours ago -
Ben’s excellent adventure with Linux
by
Ben Myers
19 hours, 44 minutes ago -
Seconds are back in Windows 10!
by
Susan Bradley
2 days, 13 hours ago -
WebBrowserPassView — Take inventory of your stored passwords
by
Deanna McElveen
1 day, 7 hours ago -
OS news from WWDC 2025
by
Will Fastie
17 hours, 27 minutes ago -
Need help with graphics…
by
WSBatBytes
1 day, 21 hours ago -
AMD : Out of Bounds (OOB) read vulnerability in TPM 2.0 CVE-2025-2884
by
Alex5723
3 days, 18 hours ago -
Totally remove or disable BitLocker
by
CWBillow
2 days, 17 hours ago -
Windows 10 gets 6 years of ESU?
by
n0ads
2 days, 20 hours ago -
Apple, Google stores still offer China-based VPNs, report says
by
Nibbled To Death By Ducks
4 days, 4 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.