03-25-2019 07:46 PM - edited 02-21-2020 08:58 AM
Hello,
When clients over anyconnect try to access services via ASA, do they use the vpnfilter first or is it the ACL on interfaces that apply first?
I am confused between vpnfilter & interface ACL , both are present in our case.
Appreciate all help.
Solved! Go to Solution.
03-26-2019 02:54 AM
Hi,
If you have the command sysopt connection permit-vpn (which is enabled by default), then the interface ACLs will be ignored for VPN traffic - thus permitting all VPN traffic by default. If you have the VPN Filter configured, then this ACL will be restricting the traffic.
HTH
03-26-2019 02:54 AM
Hi,
If you have the command sysopt connection permit-vpn (which is enabled by default), then the interface ACLs will be ignored for VPN traffic - thus permitting all VPN traffic by default. If you have the VPN Filter configured, then this ACL will be restricting the traffic.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide