cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6055
Views
5
Helpful
8
Replies

Supplier remote access

JohanPlukon
Level 2
Level 2

As a production company we have may external suppliers who deliver machines or software to support our product processes.

Many of these suppliers will always try to bring their own router to be able to support the machine or software.
Often these machines or software also need to exchange data with internal machines or software.

I need your opnion here. How do you handle situations like this? What kind of policy you have here. And what is the best solution in these situations? Place them behind a separate mx for each supplier?

1 Accepted Solution

Accepted Solutions

BlakeRichardson
Meraki Community All-Star
Meraki Community All-Star

Place them behind a single MX with each on their own VLAN would be my suggestion although how many suppliers at any one time would you have onsite?

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

View solution in original post

8 Replies 8

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

I wouldn't allow third-party network equipment to be connected to your internal network.

I often put them on their own VLAN, for a VLAN separate from the internal network, and provide them with VPN access to their devices.

BlakeRichardson
Meraki Community All-Star
Meraki Community All-Star

Place them behind a single MX with each on their own VLAN would be my suggestion although how many suppliers at any one time would you have onsite?

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

It can vary, from one to ten or fifteen per location.

Depends on the level of automation within a location.

aleabrahao
Meraki Community All-Star
Meraki Community All-Star
First time I hear about a supplier installing equipment inside the infrastructure.
A network for consultants is usually used and policies are created on what should and should not be accessed.
I am not a Cisco employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Then you have the same thought as me. But it is something that has been accepted for years, but in my opnion cant be any more.

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

I agree. The threat landscape has evolved, and security systems and practices must evolve as a result.

pavement
Level 5
Level 5

agree with everyone, set up a separate VLAN just for them and if not required, just hand out a static IP.

JohanPlukon
Level 2
Level 2

Thank you all for your answers. This helps me.