<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN tunneled traffic does not require an ACL? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263643#M1119718</link>
    <description>&lt;P&gt;Thanks for the information, I didn't know about that.&lt;BR /&gt;However, in my case there is no this command entered, and still all traffic destined to and from the tunnel passes correctly.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2025 19:48:30 GMT</pubDate>
    <dc:creator>krzysztofmaciejewskiit</dc:creator>
    <dc:date>2025-02-21T19:48:30Z</dc:date>
    <item>
      <title>IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263641#M1119716</link>
      <description>&lt;P&gt;I tested today the establishment of a Route Based IPsec VPN between the ASA and the FTD.&lt;BR /&gt;Everything works fine however I was surprised that on the ASA I didn't have to add a single ACL.&lt;BR /&gt;I wonder if traffic destined to the tunnel is treated like traffic from a higher security "zone" to a lower security "zone"?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 19:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263641#M1119716</guid>
      <dc:creator>krzysztofmaciejewskiit</dc:creator>
      <dc:date>2025-02-21T19:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263642#M1119717</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1608770"&gt;@krzysztofmaciejewskiit&lt;/a&gt;&amp;nbsp;Access control lists can be applied on a VTI interface to control traffic through VTI. To permit any packets that come from an IPsec tunnel &lt;U&gt;without&lt;/U&gt; checking ACLs for the source and destination interfaces, the &lt;STRONG&gt;sysopt connection permit-vpn&lt;/STRONG&gt; command is used.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 19:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263642#M1119717</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-02-21T19:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263643#M1119718</link>
      <description>&lt;P&gt;Thanks for the information, I didn't know about that.&lt;BR /&gt;However, in my case there is no this command entered, and still all traffic destined to and from the tunnel passes correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 19:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263643#M1119718</guid>
      <dc:creator>krzysztofmaciejewskiit</dc:creator>
      <dc:date>2025-02-21T19:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263646#M1119719</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1608770"&gt;@krzysztofmaciejewskiit&lt;/a&gt; it's enabled as default, it would only appear in the configuration if it explictly disabled.&lt;/P&gt;
&lt;PRE&gt;ASA(config)# no sysopt connection permit-vpn&lt;BR /&gt;ASA(config)# show run | i sysopt&lt;BR /&gt;no sysopt connection permit-vpn&lt;BR /&gt;ASA(config)#&lt;BR /&gt;ASA(config)# sysopt connection permit-vpn&lt;BR /&gt;ASA(config)# show run | i sysopt&lt;BR /&gt;ASA(config)#&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;So if you cannot see it in the configuration it is enabled.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 19:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263646#M1119719</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-02-21T19:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263652#M1119720</link>
      <description>&lt;P&gt;A very interesting one. Thanks for the helpful reply!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263652#M1119720</guid>
      <dc:creator>krzysztofmaciejewskiit</dc:creator>
      <dc:date>2025-02-21T20:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263653#M1119721</link>
      <description>&lt;P&gt;Sysop connection not work and not effect route based vpn in FTD (use zone)&lt;/P&gt;
&lt;P&gt;You need ACP' or you already use prefilter pass all traffic in ftd&lt;/P&gt;
&lt;P&gt;For ASA I think you need it.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263653#M1119721</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-02-21T20:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263654#M1119722</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/216276-configure-route-based-site-to-site-vpn-t.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/216276-configure-route-based-site-to-site-vpn-t.html&lt;/A&gt; &amp;lt;&amp;lt;- the note I mentioned above list here.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263654#M1119722</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-02-21T20:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263656#M1119723</link>
      <description>&lt;P&gt;Yes, on FTD I intentionally allowed this traffic using Access Control. However, on the ASA I did nothing completely, no ACLs or using the sysopt command.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263656#M1119723</guid>
      <dc:creator>krzysztofmaciejewskiit</dc:creator>
      <dc:date>2025-02-21T20:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263659#M1119724</link>
      <description>&lt;P&gt;Check below&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263659#M1119724</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-02-21T20:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263660#M1119725</link>
      <description>&lt;P&gt;I explain why in my second comments'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use show interface ip breif check secuirty level.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:21:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263660#M1119725</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-02-21T20:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263661#M1119726</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;DIV class="lia-message-body"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;For ASA if you not specify secuirty level then it by defualt set to 100 and I think it same as inside interface.&lt;/P&gt;
&lt;P&gt;This with use same secuirty inter will make traffic pass from inside to vti.&lt;/P&gt;
&lt;P&gt;Abd hence also sysop no have any effect here.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;No actually By default, the security level for VTI interfaces is 0. You cannot configure the security level.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263661#M1119726</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-02-21T20:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263663#M1119727</link>
      <description>&lt;P&gt;security levels are set manually, zone inside 90, outside 10.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263663#M1119727</guid>
      <dc:creator>krzysztofmaciejewskiit</dc:creator>
      <dc:date>2025-02-21T20:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263671#M1119728</link>
      <description>&lt;P&gt;Yes as Mr Rob mention and check vti level is 0 by defualt.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Traffic initiate from asa inside to vti&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;So from inside 90 to 0 allow by defualt (no need sysop here)&lt;/P&gt;
&lt;P&gt;And retrun traffic is allow since it have conn&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For traffic initiate from FTD&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The traffic from 0 to 90 is not allow unless you use sysop (by defualt enable)&lt;/P&gt;
&lt;P&gt;The return traffic is allow since it have conn&lt;/P&gt;
&lt;P&gt;Thanks to all&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263671#M1119728</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-02-21T20:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunneled traffic does not require an ACL?</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263672#M1119729</link>
      <description>&lt;P&gt;All clear and logical.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 20:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunneled-traffic-does-not-require-an-acl/m-p/5263672#M1119729</guid>
      <dc:creator>krzysztofmaciejewskiit</dc:creator>
      <dc:date>2025-02-21T20:33:27Z</dc:date>
    </item>
  </channel>
</rss>

