Weft Start free trial

Blog · Guide · · 3 min read

Give a contractor one server and nothing else

Deny by default, then allow exactly what is needed: a contractor's laptop that reaches the billing server and is refused everything else on the network. Three groups-and-rules steps, tested from the laptop.

A traditional VPN gives everyone who connects the whole network. That is fine for staff and wrong for a contractor who needs one system for three weeks. Weft's policy works the other way round: once it is on, nothing is allowed unless a rule allows it. This guide gives a contractor the billing server and nothing else, then checks from the contractor's laptop.

As before, this is a real run: an office with its network behind a Weft box, two servers on that network (billing and a file server), and a Windows laptop as the contractor.

A contractor who can reach one server and nothing else A contractor's laptop at 10.252.0.2 connects through the office's Weft box, office-a, which enforces policy. The office network 10.91.0.64/28 has a billing server at 10.91.0.75 and a file server at 10.91.0.76. One rule permits the contractors group to reach the billing group on TCP port 80; the billing server answers, and the file server is blocked because nothing permits it. Contractor's laptop 10.252.0.2 group: contractors OFFICE office-a 10.91.0.70 enforces the policy tunnel office · 10.91.0.64/28 Billing 10.91.0.75 group: billing File server 10.91.0.76 in no rule tcp 80 ✓ BLOCKED The one rule: contractors → billing tcp 80 Everything else: denied.
What this guide builds: one rule, contractors to billing on TCP 80. Addresses are from our test run.

What you need

Before any policy, the laptop reached both servers: billing and the file server both answered. That is the starting point to change.

1. Name what you are protecting, and who

Open Policy. Under Groups, add a group called billing with the billing server's address as a prefix member (10.91.0.75/32), and a group called contractors with the contractor's laptop as a client member.

The Groups table: billing resolves to 10.91.0.75/32, contractors holds the client contractor-laptop and resolves to 10.252.0.2/32
"Resolves to" shows the addresses each group actually stands for, so a typo shows up here rather than as a mystery later.

Policy is still off at this point, and nothing changes on the network while you build it. You can add groups and rules, read them back, and only switch them on when they are right.

2. Allow exactly one thing

Under Rules, choose contractors to billing, protocol tcp, port 80, and press Allow.

The Rules table with one rule: contractors to billing, tcp, port 80
A rule allows one direction; replies to it are always allowed.

3. Turn it on

At the top of the page, the Mode has three settings. Log records what would be blocked and blocks nothing, which is the safe way to check a new policy against real traffic. Enforce blocks it. We went straight to enforce.

The Mode card set to enforce, with off, log and enforce buttons

Think before you press it: from this moment everything between groups that no rule allows is refused. Make sure your own staff have rules too, or put them in a group with the access they need, before enforcing.

4. Check from the contractor's laptop

billing   10.91.0.75   HTTP 200  Billing
files     10.91.0.76   BLOCKED (the operation timed out)

The billing server answers; the file server, which no rule mentions, does not. The laptop is still connected, still on the same network, and simply cannot see anything it was not given.

When the contract ends, remove the laptop from Weft on the Clients page, or just take it out of the contractors group: with policy on, a device in no group reaches nothing.

If something does not work

What you seeWhat it means
The contractor cannot reach billing eitherThe rule's port or protocol does not match what the server uses (a web server on 443, not 80, for instance).
Your own staff lost access when you enforcedThey are in no group that a rule allows. Add the rules for staff, or switch back to log while you do.
A group "resolves to" nothingIts member is wrong: a mistyped prefix, or a client that has been removed.

What you have now

A contractor with exactly the access the job needs, written down in one rule anyone can read, and revoked by removing one device. The same pattern covers a payroll provider, an auditor or a support company: one group, one rule, nothing else.