VPN and limiting internet access

I posted this under the SMB as well but wanted to post under the VPN header at the same time.
Hello all, I am very new to VPN's and Firewalls so please forgive me for lack of terminology usage.
I am part of a company that has 20 internal PC's and 25 external sites (Convienient stores) that are all now being placed on a VPN. We purchased a ASA 5510 for the office and we are placing Linksys RV042 routers at the stores. What my question is, is that we have a few stores that need limited internet access because we have Subway restaurants there and they need to download and upload at times. What I dont want is to allow full access to the net because of the chance of outside attacks or viruses.
My question is, what can be done to set the VPN in place but only allow certain access to web addresses that we say is alright to have communication with?
Is this possible and / or what else needs to be purchased?
I thank you in advance for any help you can advise on.
JJ

The problem with the internet is, how do you define this 'certain' addresses. Is this possible for you?
There is an option in VPNs called split tunneling, which has a "Exclude specified" mode, that might help.
Regards\
Farrukh

Similar Messages

  • Can I still get CS5 trial - I have limited internet access and just want software on my pc - I am only running vista so that looks to be the latest that  will work for me

    Can I still get CS5 trial - I have limited internet access and just want software on my pc - I am only running vista so that looks to be the latest that  will work for me
    If so what url do I go to as I have been round in circles and always come back to CC
    Thanks

    Downloadable installation files available:
    Suites and Programs:  CC 2014 | CC | CS6 | CS5.5 | CS5 | CS4, CS4 Web Standard | CS3
    Acrobat:  XI, X | 9,8 | 9 standard
    Premiere Elements:  13 |12 | 11, 10 | 9, 8, 7
    Photoshop Elements:  13 |12 | 11, 10 | 9,8,7
    Lightroom:  5.7.1| 5 | 4 | 3 | 2.7(win),2.7(mac)
    Captivate:  8 | 7 | 6 | 5
    Contribute:  CS5 | CS4, CS3
    Download and installation help for Adobe links
    Download and installation help for Prodesigntools links are listed on most linked pages.  They are critical; especially steps 1, 2 and 3.  If you click a link that does not have those steps listed, open a second window using the Lightroom 3 link to see those 'Important Instructions'.window using the Lightroom 3 link to see those 'Important Instructions'.

  • I received a text today while at work about iCloud keychain verification code. I have not signed up for it or anything that uses it. I work out of the city with limited internet access so not sure why I would be getting this. Is my info safe??

    I received a text today while at work about iCloud keychain verification code. I have not signed up for it or anything that uses it. I work out of the city with limited internet access so not sure why I would be getting this. I only got this number about a month ago. Apparently someone else had the number before because I get texts from his family members wondering whats going on. I got one yesterday and the person didn't seem to thrilled that the number was cutoff and today I got 2 texts about iCloud Keychain which I don't even know what it is. Seems suspicious to me. If the person who use to own the number is doing it he should know it is not his number anymore because he obviously didn't pay his bills.  I'm not too sure about iCloud Keychain so just want to know my info safe?? It says it can store credit card numbers which is what gets me worried. Frankly I think it's pretty stupid to save that kind if information with any kind of app. But I don't want some random person trying to access my personal information because they are bitter they lost their number.  Please let me know as soon as possible so I can change passwords or anything that is needed.
    thanks

    If it were me, I would go to my carrier and get a new number. Since you have only had it for a month, the inconvenience would be minimal.
    Barry

  • My mac book air connects to my network and gets internet access but time machine cannot find my airport base station to set up time machine

    My mac book air connects to my network and gets internet access but airport utility  cannot find my airport base station to set up time machine

    airport utility  cannot find my airport base station to set up time machine
    Normally, AirPort Utility is not used or needed to set up Time Machine backups......unless a default setting on the Time Capsule to Enable File Sharing has been changed.
    On the other hand, if you open AirPort Utility, a picture of the Time Capsule should be displayed. Are you saying here that the Time Capsule does not appear when you open AirPort Utility?

  • Very Limited Internet access - Download

    I am now a Full Creative Cloud member. Can I download the complete Master Collection Creative Cloud Suite package for easy install onto my computer? I have very limited internet where the work computer is. I can get broadband from another location and would like to fully download the package from there and then take to the work computer for install. Is this possible? Or is it possible to ask for the software on disc?

    G'day Mylenium,
    Cheers mate for the link, however this does not offer the 'most-up-to-date' versions of all the software on offer as a paid 'Cloud' member.
    Surely there is a way for Cloud members to download the most up to date paid software without restrictions for easy install onto a computer that does not have or very little internet access?
    My office computer is located in the country and the only internet available, and very on and off due to poor reception, is 3G mobile coverage. At $49 per month for only 3GBs, this is very expensive, so we use the internet sparingly.
    I do have access to a broadband else where to download content, but I am not allowed nor is it suitable to take along the WorkStation Rig to this broadband location to install downloaded software.
    I am happy to download the occasional update and to have the software do a monthly check in for licencing, but to have to download large files is just not possible.
    I must be missing something from Adobe, surely they have addressed this concern for others before?
    Cheers
    Michael

  • Mac and Windows internet access

    Hi
    I've got my MacBook configured to startup in Windows XP or Mac OS X. Mostly I use Mac (of course) which is where I access the internet. But I have a need to access the internet via the Windows side and it won't. I have tried the Wizard but to no avail. Has anybody any suggestions of what I need to do.
    Wendy

    Apple Setup.exe
    XP is bad on security so it may try to run automatically.
    HOW TO and more is in the Boot Camp FAQ and PDF guide (access from Boot Camp Assistant as well)
    http://www.apple.com/support/bootcamp/
    Your Mac OS X DVD has a Windows /BootCamp volume that only shows up when in Windows. You can copy that to your XP system as well and run from there.

  • Relocating and wireless internet accessibility

    I'm relocating and I'm wondering how I can find out if I have wireless internet access there and if I can keep my Fios or if I'll have to switch to another provider.
    Thanks.

    You may want to post this on the Residential side of the forum as this is for the cellular phone side.
    At the top of this screen is a tab RESIDENTIAL. Click there and you can set up an account on that side and ask your question.

  • Tips on Limiting internet access

    I hope the following helps people on limiting traffic at home, it started off as a how to, but then realised it was going to be too complicated, so i thought i would just give people some tips so they have a starting point. Please comment if you have your own guides on how to do it  Limiting internet on your local network can be a very complex issue, that is why there are software packages available such as Net Nanny that make it easier for you. If you are tech savy you can do it yourself provided that your modem supports features such as QoS, URL Filtering, WAN\LAN Firewall and Timed Profiles QoS, stands for Quality of Service meaning you can have traffic slowed if you decide you don’t want to fully ban them.URL Filtering can be used to ban only certain sites.Firewall is the enforcer of the rules.Timed profiles establish a start and end time of when certain actions should take place, for example only ban traffic between 10 AM and 7 AM If you want to do this on a cable modem make sure that your cable modem is bridged before you go out and get a router that is able to do the above functionality If you have ADSL you have two choices, either get a modem router combined or you use your existing bigpond modem and get a router. If you just get a router make sure you bridge the modem for the following to work correctly If you are stuck on how to bridge your modem the following might help http://whirlpool.net.au/wiki/adsl_modem_router_bridge_mode I have found that Billion modems work the best as they are the most feature rich and are constantly updated. They are relatively affordable and can be purchased from the likes of JMG Technology, MSY and others. For example the 8800AXL AC ADSL Router is only $144 Here is some advise on how to set it uphttp://forums.whirlpool.net.au/archive/909150    

    Good article, thank you

  • Limited internet access after installing drivers in boot camp

    I bootcamped my mac and figured out the internet connection issue. After I connected to the internet however the connection has limited acces and won't open any pages. Can anyone help me with this issue?

    Hi slausty,
    usually installing a graphic card driver in Windows should not have any effect on your OSX since the WIndows driver is only loaded and used when using Windows.
    You first might try a PRAM reset of your MBP since the display settings for OSX are stored in there.
    Next you should consider downloading the BootCamp Driver Updates 2.1 and 2.2 from Apples website.
    Before installing them though a backup of your Windows or at least make a 'System Restore Point' in Windows to revert back easier if needed.
    Regards
    Stefan

  • [SOLVED] eth0-wlan0 AP using bridge AND keep internet access

    Hi there!
    This is my very first post here, so please forgive me if I (unintentionally) violate some rule.
    I have set up my system as an eth0-wlan0 access point with hostapd using a bridge.
    The IP addresses are provided by a separate dhcp-server (router resp. cablemodem).
    My problem is: when I work on the AP I would like to have a working connection to the
    Internet/Router. But to get there I have to execute
    systemctl restart dhcpcd.service
    The AP via the eth0-wlan0 bridge keeps working and I now have a working Internet connection.
    AFAIK the dhcpcd service acts (invoked by netcfg) on the bridge-profile to assign an IP
    to eth0. After that the bridge is set up and (now hostapd.service is up) the wlan0 is
    added to the bridge in AP mode.
    It would be great if someone could point out the problem for me.
    Thx, Benedikt
    Last edited by benedikt (2013-04-30 19:16:43)

    After switching from netcfg to netctl everything worked "out-of-the-box". The bridge gets to be the new standard network interface and all traffic on the machine gets directed through it. YAY

  • Monitoring and controlling internet access for router

    Im kinda confused about what im doing but i have neighbors next door that are bumming off of my internet and i want to be able to deny the access of their computers.  i tried changing the password but it seems that it didnt help, i dont know why or how they got around it but if someone could tell me how i could block their computers from accessing my router it would be greatly appreciated. thanks.

    The details of this depends on what kind of router you have, but generally the most secure setup is to only allow specific MAC addresses to use your router.  This can be a pain until you have added all of your devices - and if you have occasional users like friends who drop by it's annoying to have to go into the router and add them.  Still, it's the only sure-fire way to keep everyone else out.  In my router, it's under advanced wireless settings, and the function is called Setup Access List.
    Bill

  • HT3728 No status light at all on Airport/Time capsule. I can plug internet cable directly into bac of my MAC and have internet access no problem. Is my Airport dead and need to be replaced??

    I have NO status light on my Airport/Time Machine, I unplugged the internet connection from back of Airport and plugged directly into my MAC and am able to get to the internet just fine.
    The Airport is almost 6 years old
    Is my Airport dead and just need to get a new one??

    Is my Airport dead and just need to get a new one??
    Unfortunately, yes.  On the upside, your Time Capsule lasted about twice as long as normal.

  • Time capsule backup failure after moving and changing internet access

    I bought a 1GB time capsule to backup my MacBook Pro using time machine and also archived files so I would have these when I had to move across country to work temporarily. The time capsule was working fine in my home after the original backup through an ATT DSL, but I then moved across country and set up a Comcast cable DSL and now Time machine records under Backing up: Preparing and the latest backup records failure. Is there a way of fixing this without erasing the entire Time Capsule and then taking 2-3 days of backing up again and will I have access to these when I return to my original home with the capsule and MacBook Pro. I have tried resetting all the backup modes and options.

    Linda,
    According to the logs, you are going to need to initiate a backup, and then let it do it's thing uninterrupted, perhaps all day of over night. Time Machine needs to do a "deep traversal". See this article.
    *_Time Machine May Report "Preparing..." For a Long Time_*
    First, it’s good to determine WHY Time Machine is "Preparing..." for an extended period of time. Examining the Console logs during this event can reveal what is actually going on behind the scenes. It may be “Preparing…” for a genuinely good reason. How long is 'too long' to wait for Time Machine to finish "Preparing..."? Some times, "Preparing..." is required to perform the normal housekeeping that Time Machine does periodically. Other times, it really is "stuck" and never proceeds after many hours.
    *”Deep Traversal” (Recent Crash / Forced Restart / System Update / Extended Period Between Backups)*
    According to the following KB article it can sometimes take quite a long time if Time Machine begins a “deep traversal” and has to compare data inventories. This may apply to your situation, particularly if many Gigs of data are involved. [http://support.apple.com/kb/TS1516]
    You see, Time Machine *+does not+* ordinarily perform file-by-file comparisons to determine what has changed and thus determine what needs to be backed up. Rather, Time Machine relies on FSEvents notifications. This is a log that the system uses to keep track of changes to directories. Rather than scan tens of thousands of files for changes each time, Time Machine simply looks at this log and narrows its’ scan to only the directories that have experienced changes since the last backup. Otherwise, Time Machine would have to be running constantly just to catch every change on its own and thus eat up precious CPU.
    Every event that FSEvents records has its’ own ID which includes a time stamp. At the end of every backup, Time Machine stores the last event ID that it processes. When the next backup is initiated, Time Machine looks at this stored ID and determines that it only needs to backup events that have occurred after the time stamp on this last event ID.
    If, due to a system crash, power failure, forced restart, or some other major system event, Time Machine cannot find this last event ID in the system logs then it will consider the FSEvents log “untrustable” and it will go into what’s called “deep traversal”. The Console logs may report +“Event store UUIDs don't match”.+ In this event, Time Machine will by-pass the system log entirely and perform its’ own file-by-file comparison to determine what has changed since its’ last backup. Obviously, if tens or hundreds of Gigs are involved, then this process can take quite some time and should be allowed to proceed.
    Additionally, it appears that if Time Machine has to go back too far to find the last event ID, then it will give up and simply go into “deep traversal” and do the file-by-file scan on its’ own. This can occur if Time Machine has not been able to perform its’ hourly backups for some time, as is the case for users who only backup once a week or so. This is also the case with major Mac OS system updates that change thousands of files at one time. There are simply too many events logged by the system for Time Machine to bother looking for the last known event ID.
    Cheers!

  • Limited Internet Access -- Cannot resolve names but can ping IP addresses

    Hi,
    I'm almost at wits end here with the problem I'm having with my MBP running 10.6.7. Here's what's happened on my end:
    I'm an IT professional working with both mac, linux and PC. I upgraded to 10.6.7 a few weeks ago and everything was fine. As a part of my job I volunteered to test a VPN accelerator application from Riverbed that uses one of their "Steelhead" appliances. I installed the software and was testing it when suddenly my machine froze completely and I had to force-power cycle the laptop to reboot it. When the laptop came back up, it reconnected to the network but I was unable to resolve any IP addresses from name.
    I tested the connection repeatedly. I tried different networks. Switching between hardline and wi-fi. I blew away all network configuration and started from scratch. Three times. restarted the mDNSresponder. I uninstalled the appliance software, repeated the network blow away, and tried to connect. I tried reinstalling the software - no dice. Which leaves me where I am now: making a full backup of my drive and important information and formatting it.
    I was hoping beyond hope that someone could point out a possible solution that doesn't involve the nuclear option on my files. I have a lot of applications installed and it will take DAYS of work just to get the machine back to where its supposed to be. I dare not reinstall from a full backup because I don't know which touched file is the culprit in my painful experience.
    At the time when my PC crashed the software was likely intercepting and rerouting name-to-ip resolution to make the accelerator work. It must have temporarily altered a core networking file somehow to accomplish the redirect. When I crashed, the file was locked in a changed state and nothing I do can alter that. I've searched the appliances' web site and scoured Google looking for some hint as to what might have went wrong and tried to find a solution, but it seems that I'm the only person to have had this issue so far - either that or the solution is hidden on page 8,137 of Googles' results after all the ads have been passed up.
    The only thing that I can think of is that my machine was running vmware at the time, and that a combination of VMNET screwing up and the Steelhead appliance application caused my machine to hose itself.
    Like I said, the only thing I haven't done is format and reinstall - something I'm loathe to do at this moment because work is very busy. I still have my bootcamp partition and I've been using that for my work. Right now I am using a borrowed Mac Air to surf the net while I trawl through the various files on my Mac partition.
    So if anyone has had the patience and fortitude to read this far, I'd greatly appreciate any help or suggestions that others might be able to offer! Especially since if I have to deal with any more problems from this VPN device it would be nice to know how to fix this issue.
    Here's a brief summary of what works:
    - Ping via IP address (any location on the net)
    - Manual entry of IP to name translations in the hosts file. (did this to re-download the 10.6.7 cumulative updater)
    - nslookup works for some god-unknown reason.
    Here's what doesn't:
    - Name resolution through web browser or ping from the terminal or network utilities.
    Thanks,
    Roger.

    Roger,
    Nslookup queries the DNS server directly, while other programs (e.g. web browser, ping, etc.) use a system call (gethostname2) which goes through Apple's DirectoryService. The fact that both your VM's and nslookup are working indicates your computer can contact the DNS server via UDP and that the problem probably lies with DirectoryServices.
    Do you have a VPN client installed (something other than Steelhead)? VPN clients modify DNS resolution in order to give you name lookup for servers within the VPN. If you do have a VPN client installed, have you tried uninstalling/ reinstalling it?
    Another approach is to enable DirectoryService verbose logging from the terminal:
    sudo killall -USR1 DirectoryService
    Try a ping and then take a look (or post) the log:
    /Library/Logs/DirectoryService/DirectoryService.debug.log
    -Brendan

  • VPN and Satellite Internet

    Is this possible? I have a vpn connection currently w/ broadband internet. Moving to rural area. Can only get satellite internet. Is there one satellite internet service that is compatible with a vpn connection?

    You'd have to check with each specific provider to see what they recommend.
    One option is to use SSL vpn instead of ipsec.

Maybe you are looking for

  • How do I erase the Hard drive????

    My iBook is about 4 or 5 years old with a brand new 80GB hard drive and brand new Charger plug. Now my logic board is broken and I don't want to put any more money in fixing it. So I just want to sell it but want to erase the hard drive first. Anybod

  • Group policy is not appliying as it should be

    Hi All, I am facing very weired problem. I have created Group Policy for WSUS named "WUAU Server Policy". But when I see the RSOP on client machine to check which policy is applied it showing me the "WUAU Server Policy". But surprising part is that t

  • PHP no longer works

    Hi, I tried to upgrade and re-install PHP as I needed gettext which isn't used in the default configuration. So I downloaded the latest version of php and did the usual ./configure, make, make install. In the configuration part I used the following:

  • Can I use the upgrade version of Lightroom 5 to do a clean install?

    Hi, I'm currently an owner of Lightroom 4 (download version, bought from adobe.com) and I'm looking to upgrade to Lightroom 5. At the same time I'm going to be 'moving' the installation to a new machine (currently it's installed on my MBA, which is g

  • Need to create multiple indexes - will this work?

    For a catalog of about 350 pages, I need both a manufacturer index and a product index. I have read some of the creative solutions already posted here and in other web discussions, and I have an idea. Why not create two Book files? one could be "Cata