<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC pass-through on Cisco 857 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135847#M1004983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, my device in opposite side is Zywall 10. I don't want to use NAT on my cisco router. I'm using routing without NAT. I have two addresses IP provided by my ISP, the first is my address gateway, this address is configured on my cisco router, and the second address is my public address IP, this address is configured in the zywall 5. the gateway of my zywall 5 is the interface ethernet of my cisco router. this configuration works fine and I can navigate with explorer. My problem is when I try to establish a tunnel IPSEC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Aug 2008 06:48:20 GMT</pubDate>
    <dc:creator>elias.manchon</dc:creator>
    <dc:date>2008-08-07T06:48:20Z</dc:date>
    <item>
      <title>IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135845#M1004980</link>
      <description>&lt;P&gt;Hello Folks!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have adquired reciently a Cisco 857 router. I want to do a VPN site to site.&lt;/P&gt;&lt;P&gt;I have configured the interface ATM0.1 with "ip unnumbered" to VLAN 1. I haven't configured the router to enable NAT or PAT. The VLAN 1 is configured with one Ip public Address of my ISP. Behind the cisco router, I have a Zywall 5, this device is my VPN gateway. Initially, it works fine with other soho router but it blocked often, for this reason, I decided to change this one for a cisco router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem now is that the router cisco doesn't permit the VPN establishment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need enable IPSEC pass-through?, How can I do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 10:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135845#M1004980</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2020-02-21T10:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135846#M1004982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you provide more details here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What device is used on the opposite site to terminate the device, Cisco?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT Traversal (NAT-T) is turned ON the IOS by default starting with 12.2(13)T.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_2t/12_2t13/feature/guide/ftipsnat.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_2t/12_2t13/feature/guide/ftipsnat.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the other side is ASA/PIX/VPNC you need to turn it on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 06:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135846#M1004982</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T06:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135847#M1004983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, my device in opposite side is Zywall 10. I don't want to use NAT on my cisco router. I'm using routing without NAT. I have two addresses IP provided by my ISP, the first is my address gateway, this address is configured on my cisco router, and the second address is my public address IP, this address is configured in the zywall 5. the gateway of my zywall 5 is the interface ethernet of my cisco router. this configuration works fine and I can navigate with explorer. My problem is when I try to establish a tunnel IPSEC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 06:48:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135847#M1004983</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T06:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135848#M1004984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Other thing. All examples about IPSEC passthrought tha I can see is with NAT/PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I Need enable NAT/PAT on my router to works IPSEC passthrough?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 06:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135848#M1004984</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T06:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135849#M1004985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh you mean IPSEC passthrough and not NAT Traversal. Can you give more details about your IP addressing ? Router Internet interface has what IP? Public Private?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router LAN interface has local IP? Then howcome the device at the back has a public IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 06:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135849#M1004985</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T06:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135850#M1004986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Farruh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the next scenary:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN -- Zywall -- Cisco 857 -- INTERNET&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Cisco 857 have the next configuration on its interfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface ATM:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ATM0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no atm ilmi-keepalive&lt;/P&gt;&lt;P&gt; dsl operating-mode auto&lt;/P&gt;&lt;P&gt; hold-queue 224 in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface ATM0.1 point-to-point&lt;/P&gt;&lt;P&gt; bandwidth 2016&lt;/P&gt;&lt;P&gt; ip unnumbered Vlan1&lt;/P&gt;&lt;P&gt; pvc 8/32&lt;/P&gt;&lt;P&gt;  encapsulation aal5snap&lt;/P&gt;&lt;P&gt;  protocol ip inarp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface VLAN 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; ip address XXX.XXX.XXX.XXX 255.255.255.192&lt;/P&gt;&lt;P&gt; hold-queue 100 out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zywall 5:&lt;/P&gt;&lt;P&gt;WAN Ip Address:&lt;/P&gt;&lt;P&gt;IP: YYY.YYY.YYY.YYY&lt;/P&gt;&lt;P&gt;netmask: 255.255.255.192&lt;/P&gt;&lt;P&gt;Gateway: XXX.XXX.XXX.XXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;YYY.YYY.YYY.YYY and the IP Address XXX.XXX.XXX.XXX are provided my telecom provider.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't ACLs by the moment. I suppose that my router is passing all traffic at behind device (Zywall).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 07:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135850#M1004986</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T07:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135851#M1004987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok thanks for the detailed post. Its pretty clear now. You had a cheap SOHO DSL Modem, you removed that and are now using your Cisco router to terminate the DSL link. You are right by default there are no ACLs on Cisco router(s). IF there are no ACLs/PAT then there is no need for ESP passthrough. That is required when you are going to the internet via PAT. All LAN users have local IP and they are overloaded/PATTED to outside (wan) interface. In your case your VPN termination device (Zywall 5) has public IP. There is no NAT/PAT or ACL. In simple words VPN should work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you have some NAT configuration on your router for LAN user to access the Internet? Can you post that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are missing something else....&lt;/P&gt;&lt;P&gt;Is it possible to debug on the ZYwall?&lt;/P&gt;&lt;P&gt;Or see the phase 2 packets.encr/decr...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 07:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135851#M1004987</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T07:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135852#M1004988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks four your.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh, Upload my Cisco setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Log of my Zywall when I try to establish a tunnel IPSEC handly, is the next:&lt;/P&gt;&lt;P&gt;1  2008-08-07 10:01:47 IKE Packet Retransmit IKE &lt;/P&gt;&lt;P&gt;2  2008-08-07 10:01:47 The cookie pair is : ----&lt;/P&gt;&lt;P&gt;3  2008-08-07 10:01:44 IKE Negotiation is in process --- --- IKE &lt;/P&gt;&lt;P&gt;4  2008-08-07 10:01:44 The cookie pair is : ----&lt;/P&gt;&lt;P&gt;5  2008-08-07 10:01:43 Send:[SA][VID][VID][VID] ----&lt;/P&gt;&lt;P&gt;6  2008-08-07 10:01:43 The cookie pair is : ----&lt;/P&gt;&lt;P&gt;7  2008-08-07 10:01:43 Send Main Mode request to [XXX.XXX.XXX.XXX] --- IKE &lt;/P&gt;&lt;P&gt;8  2008-08-07 10:01:43 Rule [VPN] Sending IKE request ---- IKE &lt;/P&gt;&lt;P&gt;9  2008-08-07 10:01:43 The cookie pair is : ----&lt;/P&gt;&lt;P&gt;10  2008-08-07 10:01:40 IKE Packet Retransmit ---- IKE &lt;/P&gt;&lt;P&gt;11  2008-08-07 10:01:40 The cookie pair is : ---- &lt;/P&gt;&lt;P&gt;12  2008-08-07 10:01:24 IKE Packet Retransmit ---- IKE &lt;/P&gt;&lt;P&gt;13  2008-08-07 10:01:24 The cookie pair is : ---- IKE &lt;/P&gt;&lt;P&gt;14  2008-08-07 10:01:21 IKE Packet Retransmit ---- IKE &lt;/P&gt;&lt;P&gt;15  2008-08-07 10:01:21 The cookie pair is : ----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, If I replace my cisco router by the old router, the tunnel is established. Therefore, the problem not is on the zywall, really?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 08:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135852#M1004988</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T08:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135853#M1004989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you ping the Public IP of the other Zywall 10 from your Zywall 5 (not from the router)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the LAN interface IP of the router set as the default gateway of your ZYwall? Can you double check? Can it ping this default gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards =&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 08:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135853#M1004989</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T08:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135854#M1004990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Farrukh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is resolved. Simply, rebooting the Zywall the problem is resolved. For this things... I love cisco more every day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue, with cisco don't had happened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 09:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135854#M1004990</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T09:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135855#M1004991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most probably it had the ARP entry for the old DSL modem (SOHO) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 09:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135855#M1004991</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T09:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135856#M1004992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The last Question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the interface where I must put my ACLs to permit the establishment between the two end points, on my router cisco 857?. Initially I have putted this ACL on the VLAN 1 interface, inbound direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 09:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135856#M1004992</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T09:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135857#M1004993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This will cover only the 'outbound' traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For inbound traffic (from the internet), apply it on the ATM sub-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 09:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135857#M1004993</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T09:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135858#M1004994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In spite of "Ip unnumbered" of this interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just, I want to control the traffic from internet only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the next ACLs, but it not works, anyone can pass traffic from internet through cisco router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are my ACLs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host xxx.xxx.xxx.xxx any&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host yyy.yyy.yyy.yyy any&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host zzz.zzz.zzz.zzz any&lt;/P&gt;&lt;P&gt;access-list 101 deny   ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have on ATM subinterface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-group 101 in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 09:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135858#M1004994</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T09:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135859#M1004995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you do 'show access-list' (do you see any hits hitcnt = xx  at the end of the ACL line?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also change the last line to:&lt;/P&gt;&lt;P&gt; access-list 101 deny ip any any log&lt;/P&gt;&lt;P&gt;and see what you get.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 10:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135859#M1004995</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T10:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135860#M1004996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Farrukh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, but where I see the log of rule "access-list 101 deny ip any any log"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 13:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135860#M1004996</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T13:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135861#M1004997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you login via console:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging console 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you login via telnet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging monitor 7&lt;/P&gt;&lt;P&gt;terminal monitor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 13:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135861#M1004997</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T13:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135862#M1004998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, ok, I have seen that it appears in console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 13:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135862#M1004998</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T13:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC pass-through on Cisco 857</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135863#M1004999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's working fine now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings!!.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 14:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-pass-through-on-cisco-857/m-p/1135863#M1004999</guid>
      <dc:creator>elias.manchon</dc:creator>
      <dc:date>2008-08-07T14:09:48Z</dc:date>
    </item>
  </channel>
</rss>

