IP Whitelisting on VPN User [message #152105] |
Thu, 30 June 2022 09:54  |
tverweij
Messages: 75 Registered: March 2010 Location: Curacao
|
|
|
|
Because the Kerio VPN Service is hosted on one specific port, it is not possible to grant access for users from specific IP addresses; when port 4090 is reachable from an IP address you can log in as any user.
So I would like to see a setting per user where I can specify from what IP addresses this user can log in (any IP address should be the default, as it is now) - this limits the possibility for misuse of leaked or guessed VPN credentials.
The same should be available on the Kerio -> Kerio tunnels; now it's checked on a certificate, but it would be safer if the source IP address could also be validated.
|
|
|