cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
652
Views
10
Helpful
2
Replies

Must you allow all ports through a firewall that is just going to pass VPN traffic

CiscoPurpleBelt
Level 6
Level 6

Let's say you have a ASA firewall in between two end points (say another firewall and router) where a IPSEC tunnel is built on - basically you have an ASA that must pass IPSEC traffic.

The ASA firewall must pass isakmp and esp services and just the subnet interesting traffic or must it pass all other ports being used as well?

1 Accepted Solution

Accepted Solutions

Hi,
The firewall rule must permit ESP and UDP/500 (and UDP/4500 if natting) between the peer (outside interfaces) IP addresses only, the interesting traffic networks would not be seen outside of the VPN tunnel so therefore you do not need to explicitly permit them on a transit firewall in between the path of the VPNs.

HTH

View solution in original post

2 Replies 2

Hi,
The firewall rule must permit ESP and UDP/500 (and UDP/4500 if natting) between the peer (outside interfaces) IP addresses only, the interesting traffic networks would not be seen outside of the VPN tunnel so therefore you do not need to explicitly permit them on a transit firewall in between the path of the VPNs.

HTH

Awesome thanks thats what i thought.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: