09-28-2023 07:16 AM - last edited on 09-28-2023 10:44 PM by Translator
Hello.
Within an ASA5525 policy based L2L VPN configuration, in that config ACL, if I insert the command...
access-list COMPANY-ACCESS-LIST extended permit ip 10.0.0.0 255.0.0.0 172.16.5.0 255.255.255.0
Will this simply passively permit any traffic from 10.0.0.0/8 to enter this tunnel if it is already routed through the tunnel, or does this aggressively route all 10.0.0.0/8 traffic through this tunnel?
(I worry that I will route my whole enterprise through this tunnel and offline the enterprise.)
Thank you.
Solved! Go to Solution.
09-28-2023 07:27 AM
It id policy based vpn ? If Yes then acl you use for policy have no effect at all in routing traffic.
You need first to route traffic through the interface that apply vpn on it then vpn will work.
09-28-2023 07:27 AM
It id policy based vpn ? If Yes then acl you use for policy have no effect at all in routing traffic.
You need first to route traffic through the interface that apply vpn on it then vpn will work.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide