Hi guys, I have 4 different AD sites each with an SSG device. It's ok for sites A and B to have full access to sites C D, but as far as the other way around we only want a couple of hosts to be able to talk to sites A and B.
I am having trouble figuring out how to set this up without having to create a ton of individual tunnel policies for each pair of server objects to talk to each other.
It would be easy if I set up a separate subnet for servers and workstations at sites C and D, but unfortuantely I have SSG5s there which would limit server to workstation communication to 100 mbits.
Is it possible to somehow configure address objects to "carve" out a small portion of the /24 subnets at sites C and D and allow those to talk freely to sites A and B?
Thanks!
Wes