Hi,
Is there anyway to use host groups in SSL VPN policy?
This thread was automatically locked due to age.
Hi,
Is there anyway to use host groups in SSL VPN policy?
why?
I would define the destination subnet within VPN-definition and allow access to selected destination-hosts via Firewall-rule.
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.
why?
I would define the destination subnet within VPN-definition and allow access to selected destination-hosts via Firewall-rule.
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.
Limit them in the Firewall after connection.
You can use the groups/users in a firewall rule as source (match user based) and use the destination as you like.
__________________________________________________________________________________________________________________
Hmmm....Interesting, so SSLVPN user are considered to be from VPN zone or LAN zone?
VPN-Users should come from VPN-Zone.
Use AD-Gruops to allow access via FW-Rule. You can only see one group per user ... but the other are loaded in the background too, so you can combine multiple rules for a single user with membership to multiple groups.
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.