cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1128
Views
5
Helpful
1
Replies

vpn filter

suthomas1
Level 6
Level 6

Hello,

When clients over anyconnect try to access services via ASA, do they use the vpnfilter first or is it the ACL on interfaces that apply first?

I am confused between vpnfilter & interface ACL ,  both are present in our case.

 

Appreciate all help.

1 Accepted Solution

Accepted Solutions

Hi,

If you have the command sysopt connection permit-vpn (which is enabled by default), then the interface ACLs will be ignored for VPN traffic - thus permitting all VPN traffic by default. If you have the VPN Filter configured, then this ACL will be restricting the traffic.

 

HTH

View solution in original post

1 Reply 1

Hi,

If you have the command sysopt connection permit-vpn (which is enabled by default), then the interface ACLs will be ignored for VPN traffic - thus permitting all VPN traffic by default. If you have the VPN Filter configured, then this ACL will be restricting the traffic.

 

HTH

Review Cisco Networking for a $25 gift card