<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SITE TO SITE VPN with access-list on the outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174678#M877818</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can add the rule , not a problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 11 Jan 2009 10:39:54 GMT</pubDate>
    <dc:creator>rickyjohnt</dc:creator>
    <dc:date>2009-01-11T10:39:54Z</dc:date>
    <item>
      <title>SITE TO SITE VPN with access-list on the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174677#M877817</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;I need to ask a simple question, &lt;/P&gt;&lt;P&gt;I have a site to site VPN, and it is working properly, &lt;/P&gt;&lt;P&gt;If i want to add an access-list on the outside interface of the firewall for the incoming traffic, does it affect the VPN Traffic? i have to permit anything related to the VPN in the access-list??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174677#M877817</guid>
      <dc:creator>jorjes1984</dc:creator>
      <dc:date>2019-03-11T14:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: SITE TO SITE VPN with access-list on the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174678#M877818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can add the rule , not a problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2009 10:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174678#M877818</guid>
      <dc:creator>rickyjohnt</dc:creator>
      <dc:date>2009-01-11T10:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: SITE TO SITE VPN with access-list on the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174679#M877819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Add the rule without adding anything related to the VPN, yah?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2009 10:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174679#M877819</guid>
      <dc:creator>jorjes1984</dc:creator>
      <dc:date>2009-01-11T10:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: SITE TO SITE VPN with access-list on the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174680#M877820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Jorjes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;         if you have given "sysopt connection permit-ipsec " in  global configuration mode of the device to allow the  VPN traffic to bypass interface access lists, none of the access-list at the interface will block your VPN traffic.&lt;/P&gt;&lt;P&gt;Please visit the following url for more info&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa81/command/ref/s8.html#wp1381414" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/command/ref/s8.html#wp1381414&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jithesh K Joy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 07:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174680#M877820</guid>
      <dc:creator>Jithesh K Joy</dc:creator>
      <dc:date>2009-01-12T07:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: SITE TO SITE VPN with access-list on the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174681#M877821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Jithesh is right. if you use the command "sysopt connection permit-ipsec " all interface acls will be bypassed by vpn traffic. &lt;/P&gt;&lt;P&gt;if you are using os 7.x and greater, there is a new command under the group policy for each VPN that can effectively filter traffic for each VPN. it is the "vpn-filter" command.&lt;/P&gt;&lt;P&gt;check out the link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/uz_72.html#wp1411607" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/uz_72.html#wp1411607&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 11:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-access-list-on-the-outside-interface/m-p/1174681#M877821</guid>
      <dc:creator>akin_lopez</dc:creator>
      <dc:date>2009-01-12T11:07:51Z</dc:date>
    </item>
  </channel>
</rss>

