I have been handed a task from my predecessor that I am really at a loss on. I need to set up an "extranet" for clients outside of my company to connect to, but make sure that they do not have any access to any of my internal servers, etc. The servers they need access to are on a seperate subnet, etc. and will be setup in my current DMZ. I am using an ASA to terminate VPN clients, as well as L2L connections. Here's my question:
If I give these people VPN clients to connect to the extranet and then just specify that subnet as "interesting traffic" should that be secure enough? Or where would I start to get this setup?