Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Site-to-Site vpn to a single host on 5505?

Status
Not open for further replies.

wellerw

MIS
Mar 14, 2003
175
GB
Hi,

does anyone know if it would be possible to set up a site-to-site on an ASA5505 so that the remote network could only access a single host on the Lan.

could it be as simple as entering the host address/mask into the 'protected network' section when configuring the vpn?

If not , could I create the vpn as normal , then use access lists to restrict the access from the remote network?


Many thanks,
W
 
the interesting traffic in the crypto acl should include only the one host (the same will go for your acl for bypassing NAT). one thing you have to know is that once somone accesses the destination computer they may be able to use that to jump to other computers within the destination network.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Set it up similar to this -

Or if you control both ends, just put an ACL on the opposite end tunnel's inside interface that restricts traffic to your other network (allow the one IP and deny all others in the subnet.)


Brent
Systems Engineer / Consultant
CCNP, CCSP
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top