cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2378
Views
15
Helpful
2
Replies

IPSEC Tunnel Interesting traffic IPs seen?

CiscoBrownBelt
Level 6
Level 6

So if there is another FW in between 2 Fws and/or routers that have a IPSEC tunnel built between them, can a FW that sits between (transport device that passed the traffic to and from) see the interesting IP traffic (source IPs and destinations of interesting traffic, not just tunnel peer ip addresses)?

2 Accepted Solutions

Accepted Solutions

Hi,
No, all those intermediate routers/firewalls will see is ESP or UDP/4500 encrypted traffic between the VPN peer IP addresses. The interesting traffic will be encapsulated inside the encrypted VPN tunnel.

HTH

View solution in original post

Just to add to what @Rob Ingram has posted, they might also see UDP/500, UDP/4500 will be seen if NAT traversal is configured (enabled by default) and there is a NAT device in the path between the VPN headends.  Otherwise nothing within the VPN tunnel is seen by other devices in the path.

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

2 Replies 2

Hi,
No, all those intermediate routers/firewalls will see is ESP or UDP/4500 encrypted traffic between the VPN peer IP addresses. The interesting traffic will be encapsulated inside the encrypted VPN tunnel.

HTH

Just to add to what @Rob Ingram has posted, they might also see UDP/500, UDP/4500 will be seen if NAT traversal is configured (enabled by default) and there is a NAT device in the path between the VPN headends.  Otherwise nothing within the VPN tunnel is seen by other devices in the path.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card