Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

limit ip VPN clients can connect to

Status
Not open for further replies.

caswcu

Technical User
Feb 16, 2005
93
US
how can I limit what ips a VPN group is allowed to connect to?
 
Well, it is a bit tricky, one way is to do a split tunnel and only tunnel the ips you want them to be able to reach, another would be disabling "sysopt connection permit-ipsec", this will make the traffic inspected by the outside acl before entering your lan, just remember that you also have to enable udp500/esp from any, since you probably dont know the clients public ips beforehand.

Jan


Network Systems Engineer
CCNA/CQS/CCSP/Infosec
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top