DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

IPSEC VPN restrict LAN access ?

  • ttmt
  • Topic Author
  • User is blocked
  • User is blocked
More
04 Jul 2016 09:09 #1 by ttmt
IPSEC VPN restrict LAN access ? was created by ttmt
Hi
I'm thinking about getting a draytek 2860 router to replace an Asus RT 68AC

What I'd like to do is use the IPSEC VPN to connect to a remote site, but I only want that to have specific access to my LAN.
Can I configure it to only be able to talk to specific IP Addresses ? or certain port based VLANs ?

Thanks

Please Log in or Create an account to join the conversation.

More
04 Jul 2016 15:31 #2 by admin3
Replied by admin3 on topic Re: IPSEC VPN restrict LAN access ?
Access through the VPN tunnel can be restricted based on LAN IP/subnet when creating the tunnel.
It can also be done using the firewall (which is what I recommend) by making filter rules to control access between the networks, with the filter rule direction of "LAN/RT/VPN > LAN/RT/VPN" for LAN to LAN VPN traffic.



Forum Administrator

Please Log in or Create an account to join the conversation.

  • ttmt
  • Topic Author
  • User is blocked
  • User is blocked
More
05 Jul 2016 12:34 #3 by ttmt
Replied by ttmt on topic Re: IPSEC VPN restrict LAN access ?
Thanks - will this work if all LAN devices are in the same IP Range 192.168.1.xxx, but I only want the VPN to have access to 192.168.1.11/12 ?

Please Log in or Create an account to join the conversation.

More
05 Jul 2016 15:00 #4 by admin3
Replied by admin3 on topic Re: IPSEC VPN restrict LAN access ?
Yes, you could create a filter rule to allow access to those two IPs (either as a range or individual IP objects), then a rule after that would block access to the rest of the subnet.



Forum Administrator

Please Log in or Create an account to join the conversation.