Question in a nutshell:
How can I limit the opening of PPTP session to a given interface?
Let me explain:
I got Intern, Extern and DMZ. So I activate PPTP to allow Intern users to access DMZ. The reason to use PPTP is that I must encript the traffic from Intern users to DMZ. So a rule like "PPTP-Poll Any DMZ Allow" is defined.
Now, as a side effect a user from Extern can start a PPTP session and access DMZ what shouldn't be allowed.
I tried to solve it by setting up a rule like "Any PPTP Extern_Interface_ Drop" but is not working. I think you cannot set up rules like that since you are trying to block services in a interface address of the firewall which I think doesn't work.
Any idea to avoid connections to PPTP comming from networks different than Intern???
Thank you.
This thread was automatically locked due to age.