Recommended Posts

I have a server in my office which has a hardware vpn to my house (Draytek to Draytek router) . The main purpose is to allow the server to send an offsite image backup remotely to a pc at my house (which is dedicated for the purpose of image replication). It also enables me to access files on the server from home.

At home I have the backup PC, as well as a NAS drive and some other pc's connected to the same home network. All of this is working ok, except I realised the other day that all of the users in the office can access my shared folders and drives at home. In particular the backup PC is fully accessible, meaning anyone could copy or delete the server images. The backup images are encrypted, but it's obviously not an ideal situation.

What is the best way to secure the shared drive on the backup pc on my home network from users in the office, but still allow the office server to have access for the image backup?

Any help would be much appreciated.

Link to comment
https://www.neowin.net/forum/topic/1153698-hardware-vpn-and-home-security/
Share on other sites

Ideally you'd have 2 networks (via something like VLANs or such), one being the normal office network, and one being the VPN to your home server. The backup server would sit on both networks so that people at the office could access it, while they couldn't access the VPN network, and vice versa.

"Permit traffic only originating from the server on the office subnet to cross the tunnel."

There you go, that is how you would do it. You have a site to site setup -- so for example on a pfsense box vpn, I can create rules to restrict who can use the vpn connection(s)

post-14624-0-81873800-1369223608.jpg

Currently I allow any IP to go out the tunnel, this is to allow me to access anything on my network, be it on the wlan, the dmz, etc. while I am connected via the vpn.

But say I wanted only 192.168.1.100 to be able to use the tunnel, I could setup a rule like this

post-14624-0-02964400-1369223729.jpg

Now only 192.168.1.100 can use the vpn interface. If you wanted to get fancier you could set destination restrictions as well. So it could only access specific ports or IPs, etc..

You will need to RTFM of your router to see if it provides such features, I would assume it does.

  • 3 weeks later...

Thanks for your help. In the end I found a setting as part of the LAN-LAN vpn connection management to set the remote netowrk IP and subnet. I set the IP address to match the servers IP address with a subnet mask of 255.255.255.255. As such now my vpn connection from the house dials to the server and when the link is established it only allows traffic from the servers IP address.

I also found this link also quite useful:

http://technet.microsoft.com/en-us/library/cc958037.aspx

This topic is now closed to further replies.
  • Posts

    • Upgrade for cheap to Windows 11 Pro or Home Edition digital license by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can save up to 94% off on a Microsoft Windows 11 Home, or Pro digital license. Upgrade your computing experience with Windows 11 Pro. This cutting-edge operating system boasts a sleek new design and advanced tools to help you work faster and smarter. From creative projects to gaming and beyond, Windows 11 delivers the power and flexibility you need to achieve your goals. With a focus on productivity, the new features are easy to learn and use, enhancing your workflow and efficiency. Whether you're a student, professional, gamer, or creative, Windows 11 Home has everything you need to take your productivity to the next level. New interface. easier on the eyes & easier to use Biometrics login*.Encrypted authentication & advanced antivirus defenses DirectX 12 Ultimate. Play the latest games with graphics that rival reality. DirectX 12 Ultimate comes ready to maximize your hardware* Screen space. Snap layouts, desktops & seamless redocking Widgets. Stay up-to-date with the content you love & the new you care about Microsoft Teams. Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar** Wake & lock. Automatically wake up when you approach and lock when you leave Smart App Control. Provides a layer of security by only permitting apps with good reputations to be installed Windows Studio Effects. Designed with Background Blur, Eye Contact, Voice Focus, & Automatic Framing Touchscreen. For a true mouse-less or keyboard-less experience TPM 2.0. Helps prevent unwanted tampering Windows 11 Pro also includes a number of productivity-focused features, such as the ability to snap multiple windows together and create custom layouts, improved voice typing, and a new, more powerful search experience. Personal and professional users will enjoy a modern and secure computing experience, with improved performance and productivity features to help users get more done. Only on Windows 11 Pro If you require enterprise-oriented features for your daily professional tasks, then Windows 11 Pro is a better option. Set up with a local account (only when set up for work or school) Join Active Directory/Azure AD Hyper-V Windows Sandbox Microsoft Remote Desktop BitLocker device encryption Windows Information Protection Mobile device management (MDM) Group Policy Enterprise State Roaming with Azure Assigned Access Dynamic Provisioning Windows Update for Business Kiosk mode Maximum RAM: 2TB Maximum no. of CPUs: 2 Maximum no. of CPU cores: 128 Good to know This license is for Windows 11 only. It is NOT intended to be used for upgrading Microsoft Office (MSO) included in Parallels Pro. However, it will still work with Parallels Pro and allow you to run Windows applications including MSO, but it DOES NOT include an upgrade MSO itself. It is still compatible with Microsoft Office ONLY if you have a separate license for it. Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: desktop Max number of device(s): 1 Version: Windows 11 Pro Updates included Queries on legality of this deal, here A Windows 11 Pro retail license normally costs $199, with Windows 11 Home usually costing $139 but you can pick either one up for just $9.97 for a limited time. For a full description, specs, and license info, click the link below. Get Windows 11 Pro for just $9.97 (was $199) Get Windows 11 Home for just $9.97 (was $139) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • Why say “Retarded” then? Lol 
    • If you don't care to read what I said, then you prove my point. Maybe written media is beyond your attention span. Titles are not summaries my friend.
    • Nobody asked... in fact, I said "I don't care about political leanings"  
    • TLDR. Here is a far better title (just a basic example): Windows 11 26H2 to allow disabling Web search results
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      524
    2. 2
      +Edouard
      203
    3. 3
      PsYcHoKiLLa
      96
    4. 4
      Michael Scrip
      82
    5. 5
      Steven P.
      68
  • Tell a friend

    Love Neowin? Tell a friend!