- Posts: 26
- Thank you received: 0
Site - Site VPN with different Access Rights.
- christiaan
- Offline
- Junior Member
Less
More
19 years 2 weeks ago #11255
by christiaan
Replied by christiaan on topic Re: Site - Site VPN with different Access Rights.
Another option would be endian firewall becuase of its enhanced features.
- christiaan
- Offline
- Junior Member
Less
More
- Posts: 26
- Thank you received: 0
19 years 2 weeks ago #11257
by christiaan
Not sure what you are trying to achieve here? Sounds overly complicated for what you state you need to achieve.
Need more info such as the network services you want to allow to your trusted/untrusted clients?
Replied by christiaan on topic Re: Site - Site VPN with different Access Rights.
how about setting up a seperate vlan that they have to plug into on a switch ( or a couple of ports on a switch) which has a dhcp scope of around 10 ips for example sake and then acl that netowkr range from the network so that it doesn't go through the vpn tunnel?????
Not sure what you are trying to achieve here? Sounds overly complicated for what you state you need to achieve.
Need more info such as the network services you want to allow to your trusted/untrusted clients?
19 years 2 weeks ago #11261
by IP-bod
Replied by IP-bod on topic Re: Site - Site VPN with different Access Rights.
apologies if i wasn't clear.
Basically i have 2 types of users.
1: untrusted - They plug into the remote LAN and access local resources and internet access.
2. trusted - same as above but they need to access corporate LAN over VPN tunnel connection which i would like to set up using a 506e or 515e.
Question is: How can I enforce a policy where by untrusted users connect to the lan but not into the corporate LAN over the vpn tunnel.
remeber i intend on setting up a site 2 site vpn soon.
Hope thats clear ??
IP-bod
Basically i have 2 types of users.
1: untrusted - They plug into the remote LAN and access local resources and internet access.
2. trusted - same as above but they need to access corporate LAN over VPN tunnel connection which i would like to set up using a 506e or 515e.
Question is: How can I enforce a policy where by untrusted users connect to the lan but not into the corporate LAN over the vpn tunnel.
remeber i intend on setting up a site 2 site vpn soon.
Hope thats clear ??
IP-bod
19 years 2 weeks ago #11262
by DaLight
Replied by DaLight on topic Re: Site - Site VPN with different Access Rights.
It's all clear now IP-bod. At your remote site, you've got two sets of users. One set will have access to the Site-Site VPN while the other set won't. I think the confusion arose because you mentioned two tunnels.
You should only need one VPN tunnel and then you could use ACLs on the firewall at the remote office to allow restrict access to the corporate LAN for the IPs of the trusted users.
You should only need one VPN tunnel and then you could use ACLs on the firewall at the remote office to allow restrict access to the corporate LAN for the IPs of the trusted users.
- christiaan
- Offline
- Junior Member
Less
More
- Posts: 26
- Thank you received: 0
19 years 2 weeks ago #11267
by christiaan
Replied by christiaan on topic Re: Site - Site VPN with different Access Rights.
If you running an MS domain then you could have a remote access group that has access via then VPN to corporate lan and limit your untrusted clients permissions to local network resources in a separate group.
Time to create page: 0.132 seconds