pr3d4t0r wrote: Anyone ?
pr3d4t0r wrote: Ahriakin, I am trying to limit access FROM the VPN client - in other words, no one at my client side should be allowed to access my network. Access TO my client site from my network should be allowed across the VPN. The whole idea is to have a one-way VPN connection to my client site, so I can freely access things at my client site from my office, but the reverse is not allowed. Of course i would like to allow specific hosts and specific services to access my lan from the vpn client.
Ahriakin wrote: It shouldn't affect your inside interface, rules you apply there should take affect. I have 4 object groups of Ports and subnets that should never pass between any clients on the firewall also another 2 listing legal inside and outside private subnets and I block all non-legal subnets access to the outside using an ACL on the inside interface with Sysopt permitting VPN traffic no the outside, works as it should (if a correctly encrypted outside subnet is not permitted as a destination on my Inside interface ACL it fails).