As the picture to display, USG5320 connects layer 2 accessing switch, this switch connects internal network server and user PC,we hope achieve a special request to behave students using PC behavior:if the students use this PC, it can only access internal network resource, if the teachers use this PC ,it not only can access internal network resource but also access external network resource.
1.3 failure symptom description
(1) we cannot achieve the request of client ,if we use packet filter to limit which is based on the source IP address. Because the IP address of the PC is fixed 192.168.1.2, no matter it is used by students or teachers, the IP address of the PC won’t be changed. No matter the students or teachers use the PC, they can access external network as long as the USG5320 allows the IP address of this PC to progress NAT tansition. So we cannot control the accessing internet behavior of the students.