01-16-2020 10:48 AM
Hello
I have Some questions regarding the VPN filter ACL Functionality.
I recently configured a Route Based VPN Tunnel between my ASA and Azure Cloud. There are two ACL's here. The INSIDE interface has an an ACL applied and then I also Put a VPN filter ACL in this route based VPN tunnel.
Local Host: 1.1.1.1
Azure Host: 2.2.2.2
The vpn filter ACL is
access-list vpnfilter extended pemit tcp host 1.1.1.1 host 2.2.2.2 eq 22
When we started testing I see the access allowed on the Interface ACL, but the access is blocked by the filter ACL
Then I was told my filter ACL is wrong and it should be put in the below way
access-list vpnfilter extended pemit tcp host 2.2.2.2 host 1.1.1.1 eq 22
Can anyone please help me understand why I should flip my filter ACL for this to work?
Thanks
Ravi
Solved! Go to Solution.
01-16-2020 12:18 PM
01-16-2020 10:54 AM
Hi,
The ASA VPN Filter is configured differently than a normal ACL, with the remote network as source and the local network as destination.
Reference here. Quote from reference - "When a vpn-filter is applied to a group-policy that governs a L2L VPN connection, the ACL should be configured with the remote network in the src_ip position of the ACL and the local network in the dest_ip position of the ACL".
HTH
01-16-2020 11:32 AM
Hello
Does this mean, irrespective of the direction of the traffic flow in the tunnel, the VPN filter ACL should always have the Remote Network as Source and the Local Network as Destination?
01-16-2020 11:35 AM
01-16-2020 12:09 PM
So, in the below VPN filter ACL traffic is allowed on Port 22 bidirectionally? (Local to Remote and Remote to Local)
access-list vpnfilter extended pemit tcp host 2.2.2.2 host 1.1.1.1 eq 22
01-16-2020 12:18 PM
01-16-2020 12:54 PM
Understood
The control on the VPN filter is defined by how you out the port.
Thank you very much
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide