Avatar billede lazarus Nybegynder
20. juni 2008 - 10:16 Der er 2 kommentarer

vpn ip begrænsning

Hvordan kan jeg begrænse folks adgang til vores netværk så de kun kan se en IP / computer på vores netværk når de logger ind via VPN ? I øjeblikket har de adgang til alle maskiner. Laver jeg denne begrænsning via Active Directory eller vores firewall, og hvor gør jeg så det ?
Avatar billede jk- Nybegynder
20. juni 2008 - 10:20 #1
Du kan lave Vlan.

Forklaring fra vikipidia:

A virtual LAN, commonly known as a VLAN, is a group of hosts with a common set of requirements that communicate as if they were attached to the same wire, regardless of their physical location. A VLAN has the same attributes as a physical LAN, but it allows for end stations to be grouped together even if they are not located on the same LAN segment. Network reconfiguration can be done through software instead of physically relocating devices.

VLANs are created to provide the segmentation services traditionally provided by routers in LAN configurations. VLANs address issues such as scalability, security, and network management. Routers in VLAN topologies provide broadcast filtering, security, address summarization, and traffic flow management. By definition, switches may not bridge IP traffic between VLANs as it would violate the integrity of the VLAN broadcast domain.

Virtual LANs are essentially Layer 2 constructs, whereas IP subnets are Layer 3 constructs. In a LAN employing VLANs, a one-to-one relationship often exists between VLANs and IP subnets, although it is possible to have multiple subnets on one VLAN or have one subnet spread across multiple VLANs. Virtual LANs and IP subnets provide independent Layer 2 and Layer 3 constructs that map to one another and this correspondence is useful during the network design process.
Avatar billede bufferzone Praktikant
20. juni 2008 - 10:22 #2
Jeg ville gøre det ved at placerer VPN gatewayen i sit eget DMZ med eget netkort i frewallen og så enten placerer den ene maskine der skal tilgås i samme dmz eller styre tilgangen til denne maskine med firewall regler så VPN forbindelsen ikke kan få kontakt til andre
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester