Hi,
I have a 1700 series router with one WAN interface and one ETHERNET interface. The WAN interface connects to a T1 line and the ETHERNET interface to a switch (local LAN).
My objective is to implement an access-list that permits incoming access (from the internet) to my servers (database, application, etc) only from select IPs. i.e., access to these servers are possible only from another network of ours (a different office) and not from anywhere else.
My question is, which would be the correct location to apply this access-list?.Would it be at the WAN interface (inbound) or at the ETHERNET interface (outbound)?. Since both will work (or so I assume), are there any advantages or disadvantages of having it at either of these locations?.
your feedback is very much appreciated. Thank you and have a great year 2003!
I have a 1700 series router with one WAN interface and one ETHERNET interface. The WAN interface connects to a T1 line and the ETHERNET interface to a switch (local LAN).
My objective is to implement an access-list that permits incoming access (from the internet) to my servers (database, application, etc) only from select IPs. i.e., access to these servers are possible only from another network of ours (a different office) and not from anywhere else.
My question is, which would be the correct location to apply this access-list?.Would it be at the WAN interface (inbound) or at the ETHERNET interface (outbound)?. Since both will work (or so I assume), are there any advantages or disadvantages of having it at either of these locations?.
your feedback is very much appreciated. Thank you and have a great year 2003!