<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L2L between IOS and ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315725#M765357</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out the "vpn-filter" command, available in the group-policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Oct 2009 10:41:15 GMT</pubDate>
    <dc:creator>Herbert Baerten</dc:creator>
    <dc:date>2009-10-12T10:41:15Z</dc:date>
    <item>
      <title>L2L between IOS and ASA</title>
      <link>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315724#M765354</link>
      <description>&lt;P&gt;I have L2L connection between ASA and Cisco router. &lt;/P&gt;&lt;P&gt;I would like to protect traffic and  give full access from PIX LAN to some hosts on the cisco router sites but not inversely. &lt;/P&gt;&lt;P&gt;How to protect the LAN network on PIX site ?&lt;/P&gt;&lt;P&gt;I couldn't find anything on pix site like tcp established in ACL  ? &lt;/P&gt;&lt;P&gt;On a cisco routers there I can easily  configure some access-list in ipsec-isakmp profile (  set ip access-group in| out ) &lt;/P&gt;&lt;P&gt;thanks in advance for any help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:25:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315724#M765354</guid>
      <dc:creator>m.michalski</dc:creator>
      <dc:date>2019-03-11T16:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: L2L between IOS and ASA</title>
      <link>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315725#M765357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out the "vpn-filter" command, available in the group-policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Oct 2009 10:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315725#M765357</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-10-12T10:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: L2L between IOS and ASA</title>
      <link>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315726#M765358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok I know about it but where may I controle tcp flags ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Oct 2009 14:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315726#M765358</guid>
      <dc:creator>m.michalski</dc:creator>
      <dc:date>2009-10-13T14:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: L2L between IOS and ASA</title>
      <link>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315727#M765359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot control TCP flags - but why would you want to do that in the first place? Note that Pix/ASA is a stateful firewall, not a packet filter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Re-reading your initial question, I think what you want to achieve can be done using "no sysopt connection permit-vpn" and then permitting/denying traffic in the ACL on the outside interface.&lt;/P&gt;&lt;P&gt;Note however that the outside ACL will apply to all inbound connections over *all* VPN tunnels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Oct 2009 19:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-between-ios-and-asa/m-p/1315727#M765359</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-10-13T19:49:50Z</dc:date>
    </item>
  </channel>
</rss>

