- Posts: 1
- Thank you received: 0
pix 506e vpn policies
18 years 8 months ago #13415
by huntin5L
pix 506e vpn policies was created by huntin5L
Need some help....So i was able to setup our pix firewall for our employees to access needed resources on our network. Now, my boss said it is not secure enough. Meaning, if an employee can vpn in, they can map to any server on the network. How can i setup a policy to give only certain users folder level access. Meaning, we only want to give them access to a particular folder they need and thats it. Anybody know how to do this? Can you even do it at the firewall level?
- Italia_NYC
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
18 years 8 months ago #13487
by Italia_NYC
Replied by Italia_NYC on topic Re: pix 506e vpn policies
If you setup an IPsec (tunnel) VPN connection for your remote users, which it sounds like you have; you are experiencing one of the down-sides of utilizing this solution. When users VPN into your organization via an IPsec tunnel, they essentially become a node on your network, just as if they were in the office. So your boss has legitimate reason for concern.
This being said; if you have proper NTFS and sharing permissions established on your files/folders, then as stated above, they will be treated as if they were in the office, and whatever permissions are assigned to them, should carry through.
Your other option is an SSL based VPN for your remote users. While not as versatile as IPsec, it does have it's advantages. One of which is the client does not become a "node" on your network.
Cheers.
This being said; if you have proper NTFS and sharing permissions established on your files/folders, then as stated above, they will be treated as if they were in the office, and whatever permissions are assigned to them, should carry through.
Your other option is an SSL based VPN for your remote users. While not as versatile as IPsec, it does have it's advantages. One of which is the client does not become a "node" on your network.
Cheers.
Time to create page: 0.113 seconds