<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I inspect when I use site-tosite VPN? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754081#M1003786</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi john&lt;/P&gt;&lt;P&gt;     Many thanks for your help. Now I achieve this goal. look like this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ip inspect :&lt;/P&gt;&lt;P&gt;ip inspect name GotoInternet http&lt;/P&gt;&lt;P&gt;ip inspect name GotoInternet https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To deny all traffics from untrust zone and allow necessary port for site-to-site VPN&lt;/P&gt;&lt;P&gt;ip access-list extended DenyAnyTraffic&lt;/P&gt;&lt;P&gt; permit udp host x.x.x.x any eq isakmp&lt;/P&gt;&lt;P&gt; permit udp host x.x.x.x any eq non500-isakmp&lt;/P&gt;&lt;P&gt; permit udp host x.x.x.x eq isakmp any&lt;/P&gt;&lt;P&gt; permit esp host  x.x.x.x any&lt;/P&gt;&lt;P&gt; deny   ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already created crypto map then apply  parameters to interface&lt;/P&gt;&lt;P&gt;interface Serial0/1/1&lt;/P&gt;&lt;P&gt; bandwidth 512&lt;/P&gt;&lt;P&gt; ip address y.y.y.y 255.255.255.252&lt;/P&gt;&lt;P&gt; ip access-group DenyAnyTraffic in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect GotoInternet out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; crypto map XXX&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon, you would deserve  a rating &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;L.Thot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 10 Jun 2007 07:32:30 GMT</pubDate>
    <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
    <dc:date>2007-06-10T07:32:30Z</dc:date>
    <item>
      <title>How do I inspect when I use site-tosite VPN?</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754076#M1003781</link>
      <description>&lt;P&gt;I was implementing site-to-site VPN on the ISR router(SecurityIOS) and the ASA 5510 firewall.&lt;/P&gt;&lt;P&gt;what are protocol that I need to inspect on ISR router?&lt;/P&gt;&lt;P&gt;please advices or point me to useful links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:25:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754076#M1003781</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2019-03-11T10:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do I inspect when I use site-tosite VPN?</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754077#M1003782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not entirely sure what you mean. If you mean which protocols do you need to allow for IPSEC to work &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UDP port 500 &lt;/P&gt;&lt;P&gt;ESP port 50 &lt;/P&gt;&lt;P&gt;AH port 51 ( optional as authentication is usually done with ESP). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 07:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754077#M1003782</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-06T07:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I inspect when I use site-tosite VPN?</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754078#M1003783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks Jon&lt;/P&gt;&lt;P&gt;Let me explain further. &lt;/P&gt;&lt;P&gt;I implement site-to-site VPN that working just fine.When I configure ip inspect command on router for doing a firewall on ISR router then I can't use site-to-site VPN anymore.&lt;/P&gt;&lt;P&gt;List of commands that I added on ISR router.&lt;/P&gt;&lt;P&gt;: ip inspect name myfirewall https&lt;/P&gt;&lt;P&gt;: ip inspect name myfirewall http&lt;/P&gt;&lt;P&gt;: ip inspect name myfirewall isakmp&lt;/P&gt;&lt;P&gt;: ip inspect name myfirewall ipsec-msft&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still can't work. what is command that I need to add?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 08:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754078#M1003783</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2007-06-06T08:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I inspect when I use site-tosite VPN?</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754079#M1003784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you are using inspect what does your access-list that you use allow. You will need to allow the ports and protocols in that access-list before you add a deny any any.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense ?. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not could you post your router config minus any sensitive information. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 08:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754079#M1003784</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-06T08:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I inspect when I use site-tosite VPN?</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754080#M1003785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sidenote:&lt;/P&gt;&lt;P&gt;i dont think ASA's support AH, but that seems irrelevant to this thread.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 12:45:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754080#M1003785</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-06-06T12:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do I inspect when I use site-tosite VPN?</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754081#M1003786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi john&lt;/P&gt;&lt;P&gt;     Many thanks for your help. Now I achieve this goal. look like this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ip inspect :&lt;/P&gt;&lt;P&gt;ip inspect name GotoInternet http&lt;/P&gt;&lt;P&gt;ip inspect name GotoInternet https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To deny all traffics from untrust zone and allow necessary port for site-to-site VPN&lt;/P&gt;&lt;P&gt;ip access-list extended DenyAnyTraffic&lt;/P&gt;&lt;P&gt; permit udp host x.x.x.x any eq isakmp&lt;/P&gt;&lt;P&gt; permit udp host x.x.x.x any eq non500-isakmp&lt;/P&gt;&lt;P&gt; permit udp host x.x.x.x eq isakmp any&lt;/P&gt;&lt;P&gt; permit esp host  x.x.x.x any&lt;/P&gt;&lt;P&gt; deny   ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already created crypto map then apply  parameters to interface&lt;/P&gt;&lt;P&gt;interface Serial0/1/1&lt;/P&gt;&lt;P&gt; bandwidth 512&lt;/P&gt;&lt;P&gt; ip address y.y.y.y 255.255.255.252&lt;/P&gt;&lt;P&gt; ip access-group DenyAnyTraffic in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect GotoInternet out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; crypto map XXX&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon, you would deserve  a rating &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;L.Thot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2007 07:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-inspect-when-i-use-site-tosite-vpn/m-p/754081#M1003786</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2007-06-10T07:32:30Z</dc:date>
    </item>
  </channel>
</rss>

