<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic asa VPN question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/2087170#M395853</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stuart,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could use Reverse Path Check and take those ACL lines (RFC 1918 addresses.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now regarding ACL for vpn traffic, by default vpn traffic will not be inspected over the interface ACL's but you can restrict it with any of the interfaces ( remove the syspot permit vpn and that will start inspecting VPN traffic with ACL's)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Nov 2012 21:34:06 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-11-08T21:34:06Z</dc:date>
    <item>
      <title>asa VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/2087169#M395851</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I have several working VPNs between ASAs 8.4 and 8.3&lt;BR /&gt;The way this was set up is with cryptomaps that match whole subnets and ACL on the outside interface to permit from/to the RFC 1918 addresses.&lt;BR /&gt;I notice that the hit count is zero on these rules and so I wonder if they are actually necessary or doing anything.&lt;BR /&gt;&lt;BR /&gt;If they are not where can an acl be applied to restrict the VPN traffic? Outbound on the inside interface?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:20:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/2087169#M395851</guid>
      <dc:creator>Stuart Gall</dc:creator>
      <dc:date>2019-03-12T00:20:46Z</dc:date>
    </item>
    <item>
      <title>asa VPN question</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/2087170#M395853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stuart,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could use Reverse Path Check and take those ACL lines (RFC 1918 addresses.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now regarding ACL for vpn traffic, by default vpn traffic will not be inspected over the interface ACL's but you can restrict it with any of the interfaces ( remove the syspot permit vpn and that will start inspecting VPN traffic with ACL's)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 21:34:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-question/m-p/2087170#M395853</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-08T21:34:06Z</dc:date>
    </item>
  </channel>
</rss>

