Two different VPNs or something else?
in IT Support ·
wiredcanyon94 said:It's tough to give you a straight answer. You're basically asking, "Can Company X pull off Move Y?"
The problem is, you aren't telling me the name of the company, what industry they're in, their technical capabilities, or how strict their IT admins actually are about following policy.
Generally speaking, the answer is yes—any company could technically do XYZ. But whether *your* specific company will actually do it? Nobody knows, because there's just not enough info to work with.
The only person who can give you a real answer is a network admin at your firm. They're the ones who know exactly what's implemented on the hardware, how things are logged, and whether there's some kind of backdoor installed on your machine that lets them monitor your activity.
Also, regarding that port forwarding thing you asked about earlier—it doesn't apply here. Port forwarding isn't used for a VPN in your specific setup; it's for NAT, which is a different beast entirely. Just forget about port forwarding for this particular situation.
Look, I don't claim to be an expert on technical capabilities. I just know I was going through some internal testing, and they flagged a "stepping stone" attack as a potential vulnerability. I assume that means they have the ability to track something like that.
What I really want to understand is the configuration itself. That IT firm in Washington, D.C. explained it that way to me, though I haven't received all the specifics yet. Maybe they weren't strictly talking about port forwarding, but rather NAT, like you suggested.
But let's say there *is* a backdoor on my work computer. How would they tell the difference between me logging in from an IP address in the USA versus using this setup provided by the IT firm? This setup involves connecting to a specific router in America that mirrors or links back to the same router here in the USA, so the IP address remains identical. I'm not trying to hide; I just want to know if they can see—"Aha, his computer isn't actually in the USA, it's somewhere else, and the final destination is just the USA"—or how that mechanism actually works.
The IT firm back in America tells me the only way the US office would ever find out is if my ISP handed over my personal data directly. Is that actually plausible? Or could the folks in the US, looking at my WiFi configuration here in the States, see that I'm not actually where I claim to be? Or is this visibility limited strictly to a backdoor on the computer itself?