10-22-2008 01:42 PM - edited 03-04-2019 12:02 AM
Any help someone can provide would be much appreciated.
Here the issues I am having, we Have 851 connected to the net as well as a VPN tunnel to our head office. We need to restrict a group of computer form the Internet but these computers still need to have and be accessed through the VPN.
10-22-2008 01:45 PM
Tristan
When you say connected to the net do you mean the local network in the remote office or the Internet. Is the Internet access via your head office ?
Jon
10-22-2008 01:51 PM
the internet
10-22-2008 01:57 PM
Okay lets say the group of computers are a small subnet 192.168.5.0 255.255.255.240. If they are not a summarisable subnet then you may need to have individual host entries
Lets also say that HQ networks are
192.168.6.0/24
192.168.7.0/24
192.168.8.0/24
access-list 101 permit ip host 192.168.5.0 0.0.0.15 192.168.6.0 0.0.0.255
access-list 101 permit ip host 192.168.5.0 0.0.0.15 192.168.7.0 0.0.0.255
access-list 101 permit ip host 192.168.5.0 0.0.0.15 192.168.8.0 0.0.0.255
access-list 101 deny ip 192.168.5.0 0.0.0.15 any
access-list 101 permit ip any any
then on the LAN interface of your 851
int fa0/1
ip access-group 101 in
You need to allow ip from any any at the end of the acl if you have other computers in your LAN that should have access to the HQ and the net.
Jon
10-22-2008 01:53 PM
the 851 is the external router on our internet connection to that build. the head office does not have any internet access forwarded through the tunnel only intranet services
10-22-2008 01:55 PM
the 851 is the external router on our internet connection to that build. the head office does not have any internet access forwarded through the tunnel only intranet services
10-22-2008 01:55 PM
the 851 is the external router on our internet connection to that build. the head office does not have any internet access forwarded through the tunnel only intranet services
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide