DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
IPSEC VPN restrict LAN access ?
- ttmt
- Topic Author
- Offline
- Banned
Less
More
- Posts: 18
- Thank yous received: 0
04 Jul 2016 09:09 #86405
by ttmt
IPSEC VPN restrict LAN access ? was created by ttmt
Hi
I'm thinking about getting a draytek 2860 router to replace an Asus RT 68AC
What I'd like to do is use the IPSEC VPN to connect to a remote site, but I only want that to have specific access to my LAN.
Can I configure it to only be able to talk to specific IP Addresses ? or certain port based VLANs ?
Thanks
I'm thinking about getting a draytek 2860 router to replace an Asus RT 68AC
What I'd like to do is use the IPSEC VPN to connect to a remote site, but I only want that to have specific access to my LAN.
Can I configure it to only be able to talk to specific IP Addresses ? or certain port based VLANs ?
Thanks
Please Log in or Create an account to join the conversation.
- admin3
- Offline
- Site Admin
Less
More
- Posts: 604
- Thank yous received: 0
04 Jul 2016 15:31 #86411
by admin3
Forum Administrator
Replied by admin3 on topic Re: IPSEC VPN restrict LAN access ?
Access through the VPN tunnel can be restricted based on LAN IP/subnet when creating the tunnel.
It can also be done using the firewall (which is what I recommend) by making filter rules to control access between the networks, with the filter rule direction of "LAN/RT/VPN > LAN/RT/VPN" for LAN to LAN VPN traffic.
It can also be done using the firewall (which is what I recommend) by making filter rules to control access between the networks, with the filter rule direction of "LAN/RT/VPN > LAN/RT/VPN" for LAN to LAN VPN traffic.
Forum Administrator
Please Log in or Create an account to join the conversation.
- ttmt
- Topic Author
- Offline
- Banned
Less
More
- Posts: 18
- Thank yous received: 0
05 Jul 2016 12:34 #86431
by ttmt
Replied by ttmt on topic Re: IPSEC VPN restrict LAN access ?
Thanks - will this work if all LAN devices are in the same IP Range 192.168.1.xxx, but I only want the VPN to have access to 192.168.1.11/12 ?
Please Log in or Create an account to join the conversation.
- admin3
- Offline
- Site Admin
Less
More
- Posts: 604
- Thank yous received: 0
05 Jul 2016 15:00 #86432
by admin3
Forum Administrator
Replied by admin3 on topic Re: IPSEC VPN restrict LAN access ?
Yes, you could create a filter rule to allow access to those two IPs (either as a range or individual IP objects), then a rule after that would block access to the rest of the subnet.
Forum Administrator
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek