<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow which protocol for VPN tunnel in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412812#M308440</link>
    <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm going to open ports for a VPN tunnel on our ASA 5520 FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please advise if i would allow the protocol IP or GRE or both to able to run a VPN tunnel between 2 routers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit&lt;STRONG&gt; ip&lt;/STRONG&gt; host 2.2.2.2 host 1.1.1.1&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:08:16 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2019-03-12T03:08:16Z</dc:date>
    <item>
      <title>Allow which protocol for VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412812#M308440</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm going to open ports for a VPN tunnel on our ASA 5520 FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please advise if i would allow the protocol IP or GRE or both to able to run a VPN tunnel between 2 routers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit&lt;STRONG&gt; ip&lt;/STRONG&gt; host 2.2.2.2 host 1.1.1.1&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412812#M308440</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-03-12T03:08:16Z</dc:date>
    </item>
    <item>
      <title>Allow which protocol for VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412813#M308441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic to the device does not require ACLs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 03:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412813#M308441</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-22T03:40:19Z</dc:date>
    </item>
    <item>
      <title>Allow which protocol for VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412814#M308442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unless you have control plane ACL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 03:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412814#M308442</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-22T03:40:50Z</dc:date>
    </item>
    <item>
      <title>Allow which protocol for VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412815#M308443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi jumora,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i need to explicitly allow VPN ports/traffic since there's an ASA between the 2 routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i could see in our current production environment, there's ISAKMP and UDP port 4500 there were opened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do i also need to open these ports? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit udp any host HOST eq isakmp &lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit udp any host HOST eq 4500 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit gre host 62.x.x.x host 202.x.x.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 03:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412815#M308443</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-11-22T03:52:04Z</dc:date>
    </item>
    <item>
      <title>Allow which protocol for VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412816#M308444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depends on the type of VPN you are configuring on the routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GRE tunnel:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit gre host Remote_GRE host LOCAL_GRE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPSec tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit UDP host Remote_IPSec host Local_IPsec eq 500&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit UDP host Remote_IPSec host Local_IPsec eq 4500&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit ESP host Remote_IPSec host Local_IPsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version are you running on the ASA that is between the devices that will VPN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 04:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412816#M308444</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-22T04:30:08Z</dc:date>
    </item>
    <item>
      <title>Allow which protocol for VPN tunnel</title>
      <link>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412817#M308445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi jumora,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again for your reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we'll be setting up only the GRE tunnel on both routers and no IPsec involved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the tip and case resolved!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 05:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-which-protocol-for-vpn-tunnel/m-p/2412817#M308445</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-11-22T05:40:09Z</dc:date>
    </item>
  </channel>
</rss>

