Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi, I have a Cisco ISR 4451 with several internet facing VRF interfaces with crypto maps mounted and need to close all network ports other than IPsec without affecting the tunnels. An ACL directly in the interface will do the job?Thank you in advance...
Thank you, Just to confirm, if I apply+ an ACL directly on the interface, it won't affect the allowed traffic through the tunnels, i.e.crypto map MAP 5 ipsec-isakmpdescriptionset peer xxx.xxx.xxx.xxxset transform-set AES256-SHAset pfs group5set isakm...