cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
334
Views
5
Helpful
1
Replies

Stateful inspection over IP tunnel

a.lysyuk
Level 1
Level 1

Hello.

Does PIX performs ASA and stateful application inspection on traffic that is going through GRE tunnel.

Our customer want to build IP tunnel through PIX to pass routing information from dmz to inside interface. But I think that it can decrease security by not performing stateful inspection of application through the tunnel. Am I right?

Running routing protocol on PIX our customer don't like, despite PIX allow it.

Any helpful information will be appreciated.

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

No, the PIX will allow the GRE traffic through if you set it up right, but if there's a TCP session or something similar within that GRE tunnel, then the PIX won't see it.