<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Network restrictions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-network-restrictions/m-p/831316#M974232</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at this document. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080641a52.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080641a52.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It explains how to create a vpn-filter acl which is assigned to the tunnel-group to restrict traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your other option is to write the access in your outside acl. But to do this you must remove sysopt connection permit-ipsec/vpn. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you need any more help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Sep 2007 11:58:13 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-09-27T11:58:13Z</dc:date>
    <item>
      <title>VPN Network restrictions</title>
      <link>https://community.cisco.com/t5/network-security/vpn-network-restrictions/m-p/831315#M974231</link>
      <description>&lt;P&gt;My situation (I'm very new to Cisco and networking)&lt;/P&gt;&lt;P&gt;My company has some consultants who will be using the software VPN (not the SSL) to access our network through an ASA 5510.&lt;/P&gt;&lt;P&gt;I created a VPN for them and a group policy that hands out 192.168.12.xxx which is unique in our network.&lt;/P&gt;&lt;P&gt;I am trying to limit them to only 3 servers. So far I tried to set group policies, the VPN wizard, and even created an ACL in the ASA to limit 192.168.12.xxx to only the three server ip's but when I test it, it allows me to browse the entire network, we cant really use ACLs in the network to limit access and counting on AD to limit access isn't trusted enough.&lt;/P&gt;&lt;P&gt;Does the ASA 5510 have the ability to limit network access per each VPN group?&lt;/P&gt;&lt;P&gt;Is this a NAT rule maybe?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-network-restrictions/m-p/831315#M974231</guid>
      <dc:creator>ucnsbstaff</dc:creator>
      <dc:date>2019-03-11T11:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Network restrictions</title>
      <link>https://community.cisco.com/t5/network-security/vpn-network-restrictions/m-p/831316#M974232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at this document. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080641a52.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080641a52.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It explains how to create a vpn-filter acl which is assigned to the tunnel-group to restrict traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your other option is to write the access in your outside acl. But to do this you must remove sysopt connection permit-ipsec/vpn. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you need any more help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2007 11:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-network-restrictions/m-p/831316#M974232</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-09-27T11:58:13Z</dc:date>
    </item>
  </channel>
</rss>

