Got it

User identification on USG6330

Created: Sep 24, 2020 09:08:04Latest reply: Sep 25, 2020 09:29:33 378 7 0 0 0
  HiCoins as reward: 0 (problem unresolved)

Hi,

I have to do access via SecoClient for particular user to sepcific host on internal network but it doesn't work. I have user login via Radius. I also did local user but after login to VPN on this user aacount I have access to all hosts on local LAN. How it shoud be implemented right?


Regards,

Featured Answers

Recommended answer

Peterhof
Author Created Sep 25, 2020 09:29:33

Hello, @Poland_Arek!
I think that firewall think like that:
1. It found first security policy witch allow the user1 to connect to host1. But user1 want to connect to the host2. So, it didn't match. Firewall looking next policy.
2. The next policy says that any user can connect any host. It much. "I allow"!

The solution can be to add second security policy to deny user1 access anywhere after permit access host1:
1. user1 -> host1 -> permit
2. user1 -> any -> deny
3. any user -> any host -> permit

But you are advised to check also necessity of adding the policy to allow user1 to connect to the local (firewall).
View more
  • x
  • convention:

All Answers
DDSN
DDSN Admin Created Sep 24, 2020 09:13:12

Hi Poland_Arek,
Please wait patiently. Our engineers are looking for answers to your questions.
View more
  • x
  • convention:

Hi Poland_Arek,
What's your problem? Authentication failed or something else?
View more
  • x
  • convention:

Poland_Arek
Poland_Arek Created Sep 24, 2020 09:56:10 (0) (0)
Hi WDNJSQ
No, user can login correctly but I created security policy where this user is allowed to access to one host.
But after login I see that user can access to this host and the other hosts too (there is another policy for the rest of users where user=any). The policy for specific user is before policy for rest of the users. Is seems that firewall don't recognize that this user is log in.  
IndianKid
IndianKid Moderator Author Created Sep 24, 2020 10:01:45

Hi,

please make sure that the new VPN policy(only one host access) is on top of the default policy and all other policies.
View more
  • x
  • convention:

Poland_Arek
Poland_Arek Created Sep 24, 2020 11:32:50 (0) (0)
Hi,
The policy is on top. Same results.  
IndianKid
IndianKid Reply Poland_Arek  Created Sep 24, 2020 12:53:03 (0) (0)
Hi,

can you share the policy screenshot and details?
and go to policy logs and see the policy for that particular IP and check which policy using.  
Peterhof
Peterhof Author Created Sep 25, 2020 09:29:33

Hello, @Poland_Arek!
I think that firewall think like that:
1. It found first security policy witch allow the user1 to connect to host1. But user1 want to connect to the host2. So, it didn't match. Firewall looking next policy.
2. The next policy says that any user can connect any host. It much. "I allow"!

The solution can be to add second security policy to deny user1 access anywhere after permit access host1:
1. user1 -> host1 -> permit
2. user1 -> any -> deny
3. any user -> any host -> permit

But you are advised to check also necessity of adding the policy to allow user1 to connect to the local (firewall).
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.