Start a conversation

Deny user group access to specific interface

Overview

When there is a requirement to create a traffic rule for denying access between a specific user group and Network interface, Kerio Control needs a certain configuration change.

This article provides information on how to configure Traffic rules, Users, and Groups for such a scenario.

Solution

  1. Configure a separate group and include the necessary users as members.
    Screen_Shot_2020-12-18_at_12.17.26_PM.png
  2. Modify Users' configuration -> Addresses tab -> Specific MAC addresses of the user devices.
    Screen_Shot_2020-12-18_at_12.17.57_PM.png
  3. Create a dedicated Traffic Rule to deny access for the necessary group.
    Source: <Group_name>
    Destination: <Interface_Name>, firewall (depending on the environment)
    Service: Any
    Action: Deny with Log packets accounting
    Screen_Shot_2020-12-18_at_12.35.18_PM.png

Testing

Try to ping the interface in question from the user's PC that requires limited access. The network connection will be refused for the specified user group. The Filter logs will report the Deny actions.

  DENY "Deny group access" packet from KerioControl, proto:UDP, len:70, 10.10.20.12:63228 -> 10.10.20.1:53, udplen:42

Screen_Shot_2020-12-18_at_12.16.41_PM.png

Related Articles

Restrict VPN access for certain IP addresses

Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted
  3. Updated

Comments