Access List in Hub

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
daimos
Posts: 4
Joined: Tue Aug 12, 2014 11:57 am

Access List in Hub

Post by daimos » Tue Aug 12, 2014 1:35 pm

Hi.
I have one SoftEtherVPN server, one client pc and two virtual machine.
I`ve configured one hub and two users - client1 and client2.

SoftEtherVPN server - 192.168.20.10, windows server 2012R2
client pc - 192.168.20.10, windows 7
VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.10 windows 7

VPN - L2TP with pre-shared key.

When i connect from client pc with user client1 - I can ping VM1 and VM2, but i want configure Access List to I can ping only VM1 and cannot ping VM2 and other VMs.
I`ve configured 2 rules - Pass IP VM1 and Discard all destination Adresses, but in this case I cannot ping VM1!
Why?

I want that client1 can ping only VM1 and cannot ping all other machine.

I see Note: IP packets that did not match any access list items can pass
Can i change to "IP packets that did not match any access list items can DISCARD.

inten
Posts: 370
Joined: Fri Oct 18, 2013 8:15 am

Re: Access List in Hub

Post by inten » Tue Aug 12, 2014 2:28 pm

SoftEtherVPN server - 192.168.20.10, windows server 2012R2
client pc - 192.168.20.10, windows 7

---

VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.10 windows 7

---

Mistypo?
You do not have the required permissions to view the files attached to this post.

daimos
Posts: 4
Joined: Tue Aug 12, 2014 11:57 am

Re: Access List in Hub

Post by daimos » Wed Aug 13, 2014 8:29 am

Sorry :)
VM1 - IP 172.40.0.10 windows 7
VM2 - IP 172.40.0.11 windows 7
Client PC establishes VPN connection to SoftetherVPN Server and gets private ip from ip range 172.40.0.0/24

daimos
Posts: 4
Joined: Tue Aug 12, 2014 11:57 am

Re: Access List in Hub

Post by daimos » Wed Aug 13, 2014 11:50 am

When I create Access List Item with Action Pass to IP 172.40.0.10 with priority 100 - i can ping 172.40.0.10/32
After that I create Access List Item with Action Discard to IP 172.40.0.10/32 with priority 101 - and i cannot ping 172.40.0.10.
Somebody know why?

Which rules should I create, which enable connect to 172.40.0.11 and disable connect to 172.40.0.0/24 ?

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: Access List in Hub

Post by thisjun » Thu Aug 21, 2014 6:24 am

Please add a rule to pass opposite packet.

daimos
Posts: 4
Joined: Tue Aug 12, 2014 11:57 am

Re: Access List in Hub

Post by daimos » Fri Aug 22, 2014 6:29 am

I can`t do it - I should create a lot of rules.

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: Access List in Hub

Post by thisjun » Wed Sep 03, 2014 7:50 am

Why?
You should add two rules in Access List.

Post Reply