- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-21-2016 07:01 PM - edited 03-12-2019 12:39 AM
Hi everyone,
Users connect to ssl anyconnect vpn from outside network.
There is no ACL in firewall that restricts users from what they can access in the inside network.?
config has
sysopt connection permit-vpn
Routing shows
route inside 140.15.0.0 255.255.0.0 192.141.x.x
route inside 0.0.0.0 0.0.0.0 192.141.x.x tunneled
does this mean that vpn users are allowed to access everything in the network once they are connected?
Solved! Go to Solution.
- Labels:
-
NGFW Firewalls
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-21-2016 07:50 PM
Hello Mahesh,
If you have "
With that being said, what it stands for is , you don't need to explicitly allow the addresses that are required to be accessible over VPN.
Now to access the resources, you need the correct access-list and
Additionally, we restrict what can be accessed from
In essence, even if you have
Hope this helps.
Regards,
Dinesh Moudgil
P.S. Please rate helpful posts.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-22-2016 01:32 AM
Just to add to what Dinesh has already said, even though you are tunneling all traffic for AnyConnect you can use the VPN filter under group-policy to restrict access also.
--
Please remember to select a correct answer and rate helpful posts
Please remember to select a correct answer and rate helpful posts

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-21-2016 07:50 PM
Hello Mahesh,
If you have "
With that being said, what it stands for is , you don't need to explicitly allow the addresses that are required to be accessible over VPN.
Now to access the resources, you need the correct access-list and
Additionally, we restrict what can be accessed from
In essence, even if you have
Hope this helps.
Regards,
Dinesh Moudgil
P.S. Please rate helpful posts.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-29-2016 08:33 PM
Many thanks Dinesh.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-22-2016 01:32 AM
Just to add to what Dinesh has already said, even though you are tunneling all traffic for AnyConnect you can use the VPN filter under group-policy to restrict access also.
--
Please remember to select a correct answer and rate helpful posts
Please remember to select a correct answer and rate helpful posts
