Hi,Yes, you may configure only one host to communicate across the VPN tunnel, and you may define which ports to allow, specifying which are going to be the source and destination ports within their proper hosts.access-list site-A permit tcp host eq...