How to restrict PIX VPN access to only a few ports ?
From: Jim (dot_com_bust@hotmail.com)
Date: 02/13/03
- Next message: Duane Arnold: "Re: Black Ice is bad stuff! BEWARE!"
- Previous message: DougNews: "Re: Stateful Packet Inspection Firewall"
- Next in thread: SysAdm: "Re: How to restrict PIX VPN access to only a few ports ?"
- Reply: SysAdm: "Re: How to restrict PIX VPN access to only a few ports ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: dot_com_bust@hotmail.com (Jim) Date: 12 Feb 2003 15:09:19 -0800
Hi,
Can anyone give me some tips on how to limit the VPN connection to
just a few ports of an internal host through the Cisco PIX VPDN
configuration. I have a PIX 520 and configured with the standard VPDN
commands to accept VPN connection on the outside interface to the
internal network. The VPN connection worked fine. Now I would like to
limit the remote clients to only a few ports on one of the internal
host through this VPN connection. The only way I can come up with is
to limit those VPN connections to a single server. It is through the
standard access-list: permit ip host xxxx yyyy/24 (where yyyy/24 is
the VPDN pool) applied on the NAT command, thus no other internal host
is visible to the VPN clients except the target host. However, when I
tried to use port restriction in the access-list: permit tcp host xxxx
eq smtp yyyy/24 to further limit the client access to the port level,
no connectivity can be established. Is it possible to limit VPN
connection to just a few ports of an internal host? It seems any host
visible to the VPN connection is totally exposed. Thanks in advance
for any help you can offer.
Jim
- Next message: Duane Arnold: "Re: Black Ice is bad stuff! BEWARE!"
- Previous message: DougNews: "Re: Stateful Packet Inspection Firewall"
- Next in thread: SysAdm: "Re: How to restrict PIX VPN access to only a few ports ?"
- Reply: SysAdm: "Re: How to restrict PIX VPN access to only a few ports ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|