Hi.
I have one SoftEtherVPN server, one client pc and two virtual machine.
I`ve configured one hub and two users - client1 and client2.
SoftEtherVPN server - 192.168.20.10, windows server 2012R2
client pc - 192.168.20.10, windows 7
VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.10 windows 7
VPN - L2TP with pre-shared key.
When i connect from client pc with user client1 - I can ping VM1 and VM2, but i want configure Access List to I can ping only VM1 and cannot ping VM2 and other VMs.
I`ve configured 2 rules - Pass IP VM1 and Discard all destination Adresses, but in this case I cannot ping VM1!
Why?
I want that client1 can ping only VM1 and cannot ping all other machine.
I see Note: IP packets that did not match any access list items can pass
Can i change to "IP packets that did not match any access list items can DISCARD.
Access List in Hub
-
- Posts: 370
- Joined: Fri Oct 18, 2013 8:15 am
Re: Access List in Hub
SoftEtherVPN server - 192.168.20.10, windows server 2012R2
client pc - 192.168.20.10, windows 7
---
VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.10 windows 7
---
Mistypo?
client pc - 192.168.20.10, windows 7
---
VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.10 windows 7
---
Mistypo?
You do not have the required permissions to view the files attached to this post.
-
- Posts: 4
- Joined: Tue Aug 12, 2014 11:57 am
Re: Access List in Hub
Sorry :)
VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.11 windows 7
Client PC establishes VPN connection to SoftetherVPN Server and gets private ip from ip range 172.40.0.0/24
VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.11 windows 7
Client PC establishes VPN connection to SoftetherVPN Server and gets private ip from ip range 172.40.0.0/24
-
- Posts: 4
- Joined: Tue Aug 12, 2014 11:57 am
Re: Access List in Hub
When I create Access List Item with Action Pass to IP 172.40.0.10 with priority 100 - i can ping 172.40.0.10/32
After that I create Access List Item with Action Discard to IP 172.40.0.10/32 with priority 101 - and i cannot ping 172.40.0.10.
Somebody know why?
Which rules should I create, which enable connect to 172.40.0.11 and disable connect to 172.40.0.0/24 ?
After that I create Access List Item with Action Discard to IP 172.40.0.10/32 with priority 101 - and i cannot ping 172.40.0.10.
Somebody know why?
Which rules should I create, which enable connect to 172.40.0.11 and disable connect to 172.40.0.0/24 ?
-
- Posts: 2458
- Joined: Mon Feb 24, 2014 11:03 am
Re: Access List in Hub
Please add a rule to pass opposite packet.
-
- Posts: 4
- Joined: Tue Aug 12, 2014 11:57 am
Re: Access List in Hub
I can`t do it - I should create a lot of rules.
-
- Posts: 2458
- Joined: Mon Feb 24, 2014 11:03 am
Re: Access List in Hub
Why?
You should add two rules in Access List.
You should add two rules in Access List.