Solved

Cisco Pix 501 VPN Question

Posted on 2004-08-05
2
951 Views
Last Modified: 2010-04-11
I am setting up a connection between a remote office and a client.  They are going to be connecting to the Pix 501 using the Easy VPN Client.  There are about 10 servers and 50 users on the internal network.  I only want the client to have access to 2 of the servers and that's it!!  There also will be various ports open to them..  Could someone tell me the best way to go about setting this up???  I have the VPN connection working, but they are able to see everything on the network.

Thanks

Nick
0
Comment
Question by:Paisley-Consulting
2 Comments
 
LVL 36

Accepted Solution

by:
grblades earned 250 total points
ID: 11730158
Hi Paisley-Consulting,
There are two ways around this problem.

1) Configure split tunneling so that only traffic to the two internal IP addresses is sent across the VPN. You cannot restrict what ports people are permitted to connect to though.

2) Setup a Radius authentication server and configure it to issue an access-list to a particular users session. See my website for a tutorial.
http://www.gbnetwork.co.uk/networking/ciscopixvpnradius.html
0
 

Author Comment

by:Paisley-Consulting
ID: 11735220
Thank You for the quick response.  I am going to be using the split tunneling method to restrict them.

Thanks
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Manage ASA using outside IP 14 61
Interface traffic report in FortiAnalyzer 1000D 4 23
can't ssh to external IP 9 15
cannot view videos at msnbc 12 25
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question