Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX firewall w/Radius server able to only allow access to certain IP?

Status
Not open for further replies.

chipjumper

Technical User
Apr 16, 2003
7
PR
Equipemnt: PIX firewall, RADIUS server

Is it possible to only allow access for certain users (and maybe just groups) thru a VPN to a certain IP after authenticating with RADIUS?

We basically have 3 servers hooked up and only want certain users to only have access to one server.
 
Yeap... use split tunneling and include only the required server on the crypto ACL, ie: access-list split_tunnel permit ip host 10.10.10.10 <pool-address> 255.255.255.255

where 10.10.10.10 is the server's IP address.
Radius will take care of the users and the crypto ACL will only encrypt traffic destined for the server.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top