<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic     sysopt permit-vpn is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605485#M202633</link>
    <description>&lt;P&gt;it turns out I cant remove a post added by accident (this)&lt;/P&gt;</description>
    <pubDate>Mon, 08 Dec 2014 11:42:21 GMT</pubDate>
    <dc:creator>dtremolo1</dc:creator>
    <dc:date>2014-12-08T11:42:21Z</dc:date>
    <item>
      <title>Cisco ASA vpn bypass interface out acls?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605483#M202630</link>
      <description>&lt;TABLE style="border: 0px; margin: 0px; padding: 0px; font-size: 13px; vertical-align: baseline; color: rgb(68, 68, 68); font-family: 'Helvetica Neue', Arial, sans-serif; line-height: 16.8999996185303px; background-color: rgb(253, 253, 253);"&gt;&lt;TBODY style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline;"&gt;&lt;TR style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline;"&gt;&lt;TD class="votecell" style="border: 0px; margin: 0px; padding: 2px 10px 0px 0px; vertical-align: top; width: 50px;"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD class="postcell" style="border: 0px; margin: 0px; padding: 0px 0px 20px; vertical-align: top;"&gt;&lt;DIV style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline;"&gt;&lt;DIV class="post-text" itemprop="text" style="margin: 0px 5px 5px 0px; padding: 0px; border: 0px; font-size: 14px; vertical-align: baseline; width: 660px; word-wrap: break-word; line-height: 1.4em; color: rgb(17, 17, 17);"&gt;&lt;P style="margin-bottom: 1em; line-height: 19.6000003814697px; padding: 0px; border: 0px; vertical-align: baseline; clear: both;"&gt;I found by accident that access which wasn't explicitly permitted in ACLs still was able to went through. This only seem to happen when the src originates from a site-to-site vpn and a ciient vpn.&amp;nbsp;A permit rule does not increase the counter, a deny does but traffic is let through anyway.&amp;nbsp;What could be the cause of this? &amp;nbsp;&lt;STRONG&gt;I don't have sysopt permit-vpn.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 1em; line-height: 19.6000003814697px; padding: 0px; border: 0px; vertical-align: baseline; clear: both;"&gt;&lt;BR /&gt;&lt;SPAN style="line-height: 19.6000003814697px;"&gt;interface "ldap"&lt;/SPAN&gt;&lt;/P&gt;

&lt;PRE style="padding: 5px; font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; font-size: 12px; word-wrap: normal; border-width: 0px 0px 0px 2px; border-left-style: dotted; border-left-color: rgb(204, 204, 204); vertical-align: baseline; overflow: auto; width: auto; max-height: 600px; background: rgb(238, 238, 238);"&gt;
&lt;CODE style="font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; color: rgb(34, 34, 34); white-space: inherit; margin: 0px; vertical-align: baseline; background-image: none; background-attachment: initial; background-size: initial; background-origin: initial; background-clip: initial; background-position: initial; background-repeat: initial;"&gt;access-group ldap_access_in in interface ldap
&lt;STRONG&gt;access-group ldap_access_out out interface ldap
&lt;/STRONG&gt;&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P style="margin-bottom: 1em; line-height: 19.6000003814697px; padding: 0px; border: 0px; vertical-align: baseline; clear: both;"&gt;I had zero hits until I started to try ssh;&lt;/P&gt;

&lt;PRE style="padding: 5px; font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; font-size: 12px; word-wrap: normal; border-width: 0px 0px 0px 2px; border-left-style: dotted; border-left-color: rgb(204, 204, 204); vertical-align: baseline; overflow: auto; width: auto; max-height: 600px; background: rgb(238, 238, 238);"&gt;
&lt;CODE style="font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; color: rgb(34, 34, 34); white-space: inherit; margin: 0px; vertical-align: baseline; background-image: none; background-attachment: initial; background-size: initial; background-origin: initial; background-clip: initial; background-position: initial; background-repeat: initial;"&gt;access-list ldap_access_out line 1 extended deny tcp host 10.99.2.70 host 10.99.11.8 eq ssh (&lt;STRONG&gt;hitcnt=5)&lt;/STRONG&gt; 0xa18d6298 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P style="margin-bottom: 1em; line-height: 19.6000003814697px; padding: 0px; border: 0px; vertical-align: baseline; clear: both;"&gt;If I wait ten minutes without connecting, no hits. Checking on the remote host who is logged on I can see that the source address is what I expect it to be, and capture captures the traffic.&lt;/P&gt;
&lt;P style="margin-bottom: 1em; line-height: 19.6000003814697px; padding: 0px; border: 0px; vertical-align: baseline; clear: both;"&gt;4 minutes after the previous tries, I will now connect three times and check the hit count:&lt;/P&gt;

&lt;PRE style="padding: 5px; font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; font-size: 12px; word-wrap: normal; border-width: 0px 0px 0px 2px; border-left-style: dotted; border-left-color: rgb(204, 204, 204); vertical-align: baseline; overflow: auto; width: auto; max-height: 600px; background: rgb(238, 238, 238);"&gt;
&lt;CODE style="font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; color: rgb(34, 34, 34); white-space: inherit; margin: 0px; vertical-align: baseline; background-image: none; background-attachment: initial; background-size: initial; background-origin: initial; background-clip: initial; background-position: initial; background-repeat: initial;"&gt;[user@ldap0 ~]$ ssh 10.99.11.8
Last login: Thu Nov 20 13:48:34 2014 from 10.99.2.70
[user@root0 ~]$ logout
Connection to 10.99.11.8 closed.

[user@ldap0 ~]$ ssh 10.99.11.8
Last login: Thu Nov 20 13:53:23 2014 from 10.99.2.70
[user@root0 ~]$ ^C
[user@root0 ~]$ logout
Connection to 10.99.11.8 closed.

[user@ldap0 ~]$ ssh 10.99.11.8
Last login: Thu Nov 20 13:53:24 2014 from 10.99.2.70
[user@root0 ~]$ logout
Connection to 10.99.11.8 closed.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P style="margin-bottom: 1em; line-height: 19.6000003814697px; padding: 0px; border: 0px; vertical-align: baseline; clear: both;"&gt;And ...&lt;/P&gt;

&lt;PRE style="padding: 5px; font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; font-size: 12px; word-wrap: normal; border-width: 0px 0px 0px 2px; border-left-style: dotted; border-left-color: rgb(204, 204, 204); vertical-align: baseline; overflow: auto; width: auto; max-height: 600px; background: rgb(238, 238, 238);"&gt;
&lt;CODE style="font-family: 'Droid Sans Mono', Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; color: rgb(34, 34, 34); white-space: inherit; margin: 0px; vertical-align: baseline; background-image: none; background-attachment: initial; background-size: initial; background-origin: initial; background-clip: initial; background-position: initial; background-repeat: initial;"&gt;access-list ldap_access_out line 1 extended deny tcp host 10.99.2.70 host 10.99.11.8 eq ssh (hitcnt=8) 0xa18d6298 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605483#M202630</guid>
      <dc:creator>dtremolo1</dc:creator>
      <dc:date>2019-03-12T05:11:44Z</dc:date>
    </item>
    <item>
      <title>"sysopt connection permit-vpn</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605484#M202632</link>
      <description>&lt;P&gt;"sysopt connection permit-vpn" is &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/vpn/asa_91_vpn_config/vpn_ike.html#pgfId-1042737"&gt;enabled by default&lt;/A&gt;. If you want to control the traffic that is sent through the tunnel you can:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Disable it with "no sysopt connection permit-vpn" and control it with the interface ACL.&lt;/LI&gt;&lt;LI&gt;Configure a vpn-filter that is applied to a the group-policy for the tunnel-group.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 08 Dec 2014 10:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605484#M202632</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-12-08T10:01:50Z</dc:date>
    </item>
    <item>
      <title>    sysopt permit-vpn is</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605485#M202633</link>
      <description>&lt;P&gt;it turns out I cant remove a post added by accident (this)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2014 11:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605485#M202633</guid>
      <dc:creator>dtremolo1</dc:creator>
      <dc:date>2014-12-08T11:42:21Z</dc:date>
    </item>
    <item>
      <title>Thanks Karsten!</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605486#M202636</link>
      <description>&lt;P&gt;Thanks Karsten!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2014 11:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-vpn-bypass-interface-out-acls/m-p/2605486#M202636</guid>
      <dc:creator>dtremolo1</dc:creator>
      <dc:date>2014-12-08T11:42:42Z</dc:date>
    </item>
  </channel>
</rss>

