Networking Forums

Networking Forums > Computer Networking > Windows Networking > Network Access Lists

Reply
Thread Tools Display Modes

Network Access Lists

 
 
Mike
Guest
Posts: n/a

 
      08-31-2006, 01:43 AM

Is it possible (natively to windows) to create an IP based access list? That
is allow only certain other IP based machines to see this PC on my network.
Kind of like a VLAN.

For example I want the PC to have an address of 10.1.1.1 and only allow PC's
with IP 10.1.1.2 and 10.1.1.3 to communicate.



 
Reply With Quote
 
 
 
 
Miha Pihler [MVP]
Guest
Posts: n/a

 
      08-31-2006, 07:48 AM
Hi Mike,

Yes it is possbile...

Here is how (and it is the same for Windows Server 2003).

How to use IPSec IP filter lists in Windows 2000
http://support.microsoft.com/kb/313190

--
Mike
Microsoft MVP - Windows Security

"Mike" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> Is it possible (natively to windows) to create an IP based access list?
> That is allow only certain other IP based machines to see this PC on my
> network. Kind of like a VLAN.
>
> For example I want the PC to have an address of 10.1.1.1 and only allow
> PC's with IP 10.1.1.2 and 10.1.1.3 to communicate.
>
>
>



 
Reply With Quote
 
Mike
Guest
Posts: n/a

 
      09-01-2006, 05:16 AM
Hi Mike,

I did try that before posting but it didn't work.

NOTE: If you assign this policy, all traffic is allowed because there is no
Deny rule that prevents other traffic. If you want to only allow traffic
that you specified in the above policy, you must create a Deny rule that
denies all traffic.

Are you sure that line is true? Is there an order to which rules are
applied?

Regards,
Mike.


"Miha Pihler [MVP]" <mihap-(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> Hi Mike,
>
> Yes it is possbile...
>
> Here is how (and it is the same for Windows Server 2003).
>
> How to use IPSec IP filter lists in Windows 2000
> http://support.microsoft.com/kb/313190
>
> --
> Mike
> Microsoft MVP - Windows Security
>
> "Mike" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>>
>> Is it possible (natively to windows) to create an IP based access list?
>> That is allow only certain other IP based machines to see this PC on my
>> network. Kind of like a VLAN.
>>
>> For example I want the PC to have an address of 10.1.1.1 and only allow
>> PC's with IP 10.1.1.2 and 10.1.1.3 to communicate.
>>
>>
>>

>
>



 
Reply With Quote
 
Miha Pihler [MVP]
Guest
Posts: n/a

 
      09-01-2006, 07:46 AM
The article shows general process of creating rules. So if you want to
filter specific traffic -- put in deny rule...

No -- there is no rule order. System will process all allow rules first
until it hits a deny...

--
Mike
Microsoft MVP - Windows Security

"Mike" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi Mike,
>
> I did try that before posting but it didn't work.
>
> NOTE: If you assign this policy, all traffic is allowed because there is
> no Deny rule that prevents other traffic. If you want to only allow
> traffic that you specified in the above policy, you must create a Deny
> rule that denies all traffic.
>
> Are you sure that line is true? Is there an order to which rules are
> applied?
>
> Regards,
> Mike.
>
>
> "Miha Pihler [MVP]" <mihap-(E-Mail Removed)> wrote in message
> news:%(E-Mail Removed)...
>> Hi Mike,
>>
>> Yes it is possbile...
>>
>> Here is how (and it is the same for Windows Server 2003).
>>
>> How to use IPSec IP filter lists in Windows 2000
>> http://support.microsoft.com/kb/313190
>>
>> --
>> Mike
>> Microsoft MVP - Windows Security
>>
>> "Mike" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>>>
>>> Is it possible (natively to windows) to create an IP based access list?
>>> That is allow only certain other IP based machines to see this PC on my
>>> network. Kind of like a VLAN.
>>>
>>> For example I want the PC to have an address of 10.1.1.1 and only allow
>>> PC's with IP 10.1.1.2 and 10.1.1.3 to communicate.
>>>
>>>
>>>

>>
>>

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
"noname" in router network devices lists Adam Lipscombe Linux Networking 1 06-21-2007 04:51 PM
WINS and Browser Lists MarkSJ Windows Networking 1 08-21-2006 02:49 PM
Browse Lists Jeff Richardson Windows Networking 1 12-14-2005 05:08 PM
router access lists Darren Network Routers 2 11-14-2005 08:43 PM
Can Linksys broadband/wifi routers run inbound/outbound access lists? Peter Broadband 7 12-09-2003 02:50 PM



1 2 3 4 5 6 7 8 9 10 11