<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN and LAN access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537785#M1055171</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The above instructions work. How do you allow the users to terminal service to a server and then only allow them to access that server?  Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 May 2006 19:16:44 GMT</pubDate>
    <dc:creator>dianewalker</dc:creator>
    <dc:date>2006-05-12T19:16:44Z</dc:date>
    <item>
      <title>VPN and LAN access</title>
      <link>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537783#M1055167</link>
      <description>&lt;P&gt;I want to allow certain users to connect to my comncentrator, but then only allow them to have access to a single server on the LAN side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537783#M1055167</guid>
      <dc:creator>harvey.dewan</dc:creator>
      <dc:date>2020-02-21T08:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and LAN access</title>
      <link>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537784#M1055169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi  ..  you need to follow some steps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.-  create a subnet list and add the IP you need access to&lt;/P&gt;&lt;P&gt;Configuration | Policy Management | Traffic Management | Network Lists&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.-  create a group for remote access&lt;/P&gt;&lt;P&gt;Configuration | User Management | Groups &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.-  Within the group select the tab 'Client Config' select the option 'Only tunnel networks in the list'&lt;/P&gt;&lt;P&gt;and select the list you created on step 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow a remote user connect to one only host by using VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ...please rate it if it does !!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2006 05:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537784#M1055169</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-05-03T05:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and LAN access</title>
      <link>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537785#M1055171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The above instructions work. How do you allow the users to terminal service to a server and then only allow them to access that server?  Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 May 2006 19:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537785#M1055171</guid>
      <dc:creator>dianewalker</dc:creator>
      <dc:date>2006-05-12T19:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and LAN access</title>
      <link>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537786#M1055173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ...  If I understood correctly ...  you want to allow access to one server only for your remote users ..  this can be done by controlling the access at the VPN concentrator as per my previous post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you initiate another session from the above server to lets say another server by using Remote desktop .. then the VPN concentrator can do nothing about it as the traffic does not traverse it. The same applies to any device terminating the VPN connection.  to restrict further connection you need to implement some kind of HIPS ( Host intrution prevention system such as CSA ) on the desktops and servers to control that type of connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ... please rate it if it does !!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 May 2006 11:46:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537786#M1055173</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-05-14T11:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and LAN access</title>
      <link>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537787#M1055174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your prompt response and information, Fernando.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for not making my questions clear.  I want to allow the terminal service (remote desktop) to this server after the users login to VPN Concentrator, not terminal service to another server from this server.  By using the instructions from the previous post, the users can't terminal service (Remote Desktop, etc. ) to this server after they login to VPN Concentrator, but can access everything on this server. I would like to allow the users to terminal service to one server AFTER they login to VPN.  Then, I only allow them to access this server after they terminal service to this server.  Please let me know if I have not explained myself clearly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 May 2006 13:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537787#M1055174</guid>
      <dc:creator>dianewalker</dc:creator>
      <dc:date>2006-05-15T13:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and LAN access</title>
      <link>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537788#M1055175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can exclude split tunnel, that create Access list that will be aplied on tunnel traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2007 10:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-and-lan-access/m-p/537788#M1055175</guid>
      <dc:creator>fisko</dc:creator>
      <dc:date>2007-10-05T10:48:48Z</dc:date>
    </item>
  </channel>
</rss>

