<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA vpn-filter stateless? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-filter-stateless/m-p/633733#M1028801</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone have any more info on "vpn-filter"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Searched for bugs, here are a few examples:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCse67035 - If filter is applied on the vpn tunnel permititing the outbound traffic,ASA drops the packet unless the return is allowed. (JUNKED - Why?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCse74848 - Command Reference and Configuration Guide entries for vpn-filter lack clarity. The vpn-filter operates on the ingress VPN traffic and does not filter egress VPN traffic. (That would have been nice to know)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jan 2007 16:11:05 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-01-16T16:11:05Z</dc:date>
    <item>
      <title>ASA vpn-filter stateless?</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-filter-stateless/m-p/633732#M1028798</link>
      <description>&lt;P&gt;ASA 7.2.1. I have added a vpn-filter acl to a l2l tunnel-group policy. I used the following cisco document "Restrict the Network Access of Remote Access VPN Users".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080641a52.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080641a52.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is, I have to explicitly allow the return traffic from any initiated connection. For example...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 172.25.0.1 host 172.16.0.1 eq telnet&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 172.16.0.1 eq telnet host 172.25.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand the acl needs to be written bidirectional, because it is not applied into or out of an interface, but shouldn't it be stateful? If not, what's the point of the vpn-filter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my other option to remove "sysopt connection permit-ipsec" and put the vpn-filter acl's on the outside interface?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-filter-stateless/m-p/633732#M1028798</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2019-03-11T09:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA vpn-filter stateless?</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-filter-stateless/m-p/633733#M1028801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone have any more info on "vpn-filter"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Searched for bugs, here are a few examples:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCse67035 - If filter is applied on the vpn tunnel permititing the outbound traffic,ASA drops the packet unless the return is allowed. (JUNKED - Why?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCse74848 - Command Reference and Configuration Guide entries for vpn-filter lack clarity. The vpn-filter operates on the ingress VPN traffic and does not filter egress VPN traffic. (That would have been nice to know)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 16:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-filter-stateless/m-p/633733#M1028801</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-01-16T16:11:05Z</dc:date>
    </item>
  </channel>
</rss>

