cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
402
Views
5
Helpful
1
Replies

Can you Restrict a VPN user to a subnet?

lhoyle
Level 1
Level 1

We have a vendor requesting VPN access. His access needs to be limited to the subnet his products reside. We have a 3020. I cannot find how we can restrict him.

Any ideas will helpful.

Thanks,

Lee

1 Accepted Solution

Accepted Solutions

kamal-learn
Level 4
Level 4

hi

under GUI interface of your concentrator create a nework-list VENDOR where you specify the networks that can be reached by this client (allowed networks) enable (split tunneling policy) check the box (only tunnel nertwork in the list) choose the nework list that you ve created before called i.e VENDOR.

so what happens at the other side ? if he will try to access one of your networks that are not specified in your network-list the vpn client software will not tunnel that traffic instead it will be forwarded to his/her default gateway.

HTH

do rate if it does help

View solution in original post

1 Reply 1

kamal-learn
Level 4
Level 4

hi

under GUI interface of your concentrator create a nework-list VENDOR where you specify the networks that can be reached by this client (allowed networks) enable (split tunneling policy) check the box (only tunnel nertwork in the list) choose the nework list that you ve created before called i.e VENDOR.

so what happens at the other side ? if he will try to access one of your networks that are not specified in your network-list the vpn client software will not tunnel that traffic instead it will be forwarded to his/her default gateway.

HTH

do rate if it does help

Review Cisco Networking products for a $25 gift card