09-26-2020 08:37 AM
Hi all,
I have a subcontractor that I want to give limited access to one machine on my switch. The subcontractor logs in via VPN access to cisco 3825. The vpn connection has a unique subnet 192.168.x.x and routs to my layer 3 switch (3750) to a vlan 60 which is mapped to port 47. The machine has a fixed ip of 192.168.x.x
port 48 on the switch is currently configured as noswitchport and goes to the router. I considered private vlans, but I was not sure how to set it up as far as promiscuous ports and the actual port 48. I looked into access lists, but could not get the desired effect of having the machine able to be accessible by vpn and also capable of going to the internet, but no other access. I think i have been working on this too long and i am just missing a simple step. any help is appreciated.
thank you
Solved! Go to Solution.
09-26-2020 02:58 PM
Thanks Georg,
I ended up following this tutorial https://www.youtube.com/watch?v=BwEcN_bXLkw and was able to block traffic originating from the subcontractor vlan to my other vlans as you suggested.
I wonder if that is enough for security. I can still ping from machines from my other vlans to the sub's vlan...I think I can apply a similar access list on each of the other vlans.
Thanks again
09-26-2020 08:54 AM
Hello,
actually, an access list still sounds like the best option. If your VPN clients are in the 192.168.x.x range, deny ip access from this network to any other network configured on the router, and the last statement should be to allow ip access from 192.168.x.x to any.
If possible, post the full running configuration of your 3825.
09-26-2020 02:58 PM
Thanks Georg,
I ended up following this tutorial https://www.youtube.com/watch?v=BwEcN_bXLkw and was able to block traffic originating from the subcontractor vlan to my other vlans as you suggested.
I wonder if that is enough for security. I can still ping from machines from my other vlans to the sub's vlan...I think I can apply a similar access list on each of the other vlans.
Thanks again
09-26-2020 11:52 PM
Hello,
can you post the running configuration of your router, with the changes you have implemented ?
09-26-2020 02:33 PM
Hello
Can you post a topology diagram on this data flow please?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: