pptp vpn user must be limited only to access 2 ip addresses

Hi all,

I'm looking for a solution. We have a external company who installed a pc with plc controllers.
The need to maintain them and connect to them.
We need to give VPN access to them.
But we don't want this company to be able to connect to other ip addresses on our network.
Hence they could do a lot of things wrong. And we don't want that.

So, how can this be done?
We also have ISA server setup for VPN but I don't seem to find a solution to bind a user to specific IP addresses
LVL 1
osa2Asked:
Who is Participating?
 
pwindellConnect With a Mentor Commented:
1. You have to create an Account on your Domain for them to use.  Create a unique Group to go along with it and place the Account into that Group. Make that group the Default Group for that Account and then remove the Account from Domain Users Group.   Make sure the Account has Remote Access or "Dial-in" rights.

2. Create a User Object on the ISA to place the User Account (or its Group) in.

3. Create an Address Set containing the IP#s you want them to Access

4. Create an Access Rule as:

From: VPN Users
To: <aforementioned Address Set>
Users: <aforementioned User Set>
Protocols: <whatever>

5. Make sure that this Access Rule is above the other VPN Access Rule in the Rule list.  

6. Your other VPN Access Rules should also use a User Set that does not contain this user as an extra measure.      Do not allow VPN Access Rules to be anonymous ("All Users").
0
 
Keith AlabasterEnterprise ArchitectCommented:
You cannot bind a specific user to an IP address.

One option is to use RDP for the two users rather than vpn. Each user can be pointed at a workstaion internally that is locked down to what you want them to have access to.
0
All Courses

From novice to tech pro — start learning today.