DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

LAN-LAN One way Possible?

  • purelaise
  • Topic Author
  • Offline
  • New Member
  • New Member
More
09 Sep 2016 11:21 #1 by purelaise
LAN-LAN One way Possible? was created by purelaise
Hi All,

I want to setup site to site VPN tunnels from our support site to the customer end. We run into a problem where the customer site can see our entire LAN and all the machines on it.

Is there a way to stop this behavior. So we can see the sites LAN but the site cant see our machines. As we want to start sending there backups to our colo via the VPN. This is possible on a Fortinet to Draytek LAN-LAN which we have tested from another site.

Many thanks

Robin

Please Log in or Create an account to join the conversation.

More
09 Sep 2016 14:02 #2 by admin3
Replied by admin3 on topic Re: LAN-LAN One way Possible?
Set up Firewall filter rules to block traffic in that direction, so that incoming traffic from the VPN tunnel is blocked.

To do that, set up a rule in Filter set 2 with the direction of VPN > VPN
Source IP: Remote subnet
Destination IP: Local subnet
Service Type: any
Action: Block

That should then limit access over the VPN so that your network can access the remote side but the remote side cannot connect directly to your network.



Forum Administrator

Please Log in or Create an account to join the conversation.

  • purelaise
  • Topic Author
  • Offline
  • New Member
  • New Member
More
09 Sep 2016 14:28 #3 by purelaise
Replied by purelaise on topic Re: LAN-LAN One way Possible?
Thank you for your reply.

Could you point me on where to do this please?

Im using a 2830

Thank you

Please Log in or Create an account to join the conversation.

  • purelaise
  • Topic Author
  • Offline
  • New Member
  • New Member
More
09 Sep 2016 23:30 #4 by purelaise
Replied by purelaise on topic Re: LAN-LAN One way Possible?
Just an update.

I found where I needed to be. Followed your instructions to the T and it worked a treat! Thank you very much!

Please Log in or Create an account to join the conversation.