Hi,
I am trying to achieve the following;
I would like certain users of client VPN only certain access to our internal VLANs.
So I have a MX acting as my firewall connected to my Cisco CORE switch and Access switches downstream to our internal VLANs (LANs).
If I understand correctly, you can only have 1 subnet for client VPN access in right?
So based on that, is there a way to limit certain users to access only certain internal subnets only?
Example:
Bob after using client VPN can only access VLAN #11 and be denied access to all other internal VLANs
But Allice using client VPN can access all internal VLANs.
If not from above, I don't think FW rules or Cisco ACLs would work because you can only have 1 client VPN Subnet, so restricting 1 VLAN would affect everyone connecting remotely i would believe?
If not, how can I achieve this from Meraki MX firewall solution? or with Cisco switches if known as last resort?
Thank you,