Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

shadyMedia

macrumors newbie
Original poster
Apr 6, 2009
27
0
What I would like to do for better security is to limit how user's on our outside network gain access to our local LAN and services

I want it so that if a user try's connecting to a afp share they need to be connect to the VPN same for work group manager and ssh

The Server handles-

-AFP
-DHCP
-DNS
-Firewall
-NAT
-Netboot
-NFS
-OD (Open Directory)
-Software Update
-VPN


So our setup goes like this

ISP Modem-->Mac OSX Server (MacMini Server)--ASANTE GX5-2400W (24 port Giaga Bit Switch...That we need to replace soonish---And from there to the local computer's and to the AP's throughout the school

The WAN is running through a USB ethernet Adapter (Apple) and the LAN runs through the on board Ethernet plug


I'm pretty sure you can do this but i'm just not sure how
 
on your mac server enable the firewall and block any incoming traffic except vpn traffic. on the outside clients configure a vpn connection to your server's external (isp) interface and you are all set.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.