PIX Hardware Question

Posted on 2008-11-14
Last Modified: 2012-05-05
I have several VPN users on my PIX515.  Some are allowed to connect to the 192.168.10.x range and others only the 192.168.11.x range.

So my question is this, I have an access list set up for the 10 range that looks like this:

access-list 102 permit ip

BUT!  I want to add another user, and I don't want him to have access to the WHOLE 11 range, just one machine (i.e.  Am I correct in guessing that the only way to do this is to create a new access list along the lines of

access-list 103 permit ip host

and assign just him to it?   I was hoping it might be easier, but I can't think of another way to do it.

Thanks anyone!
Question by:dougp23
    1 Comment
    LVL 28

    Accepted Solution

    You could set up a split tunnel configuration for the one user that only tunnels traffic for the one IP address you want him to access.  For example:

    access-list splitTunnelAcl permit ip any
    vpngroup restricted_user split-tunnel splitTunnelAcl

    Of course, you would also need the other "vpngroup" commands for this new VPN group, but you could copy your current values into statements for this new group.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Find Ransomware Secrets With All-Source Analysis

    Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

    Suggested Solutions

    I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
    I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now