cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
424
Views
0
Helpful
1
Replies

VPN log in , but do not access to the host on specified port

Bledar Meta
Level 1
Level 1

I have configure e ipsec remote access VPN

VPN connect receieve ip from the pool i have cofigured everything is ok

I use asa as firewall and ACS for users

as you can see log from asa :

access-list #acsacl line 1 extended permit tcp 192.168.1.0 255.255.255.0 host 10.220.220.5 eq 1988 (hitcnt=0)

access-list #acsacl line 2 extended deny ip any any (hitcnt=59)

line1 does not have any hitcnt , dircetly the request goes on line 2 , the acl above is configured on ACS , so i donnt access host 10.220.220.5 on port 1988

any idea ?

1 Reply 1

Hi,

If you added the "deny ip any any" please remove it, there is an implicit deny rule by definition.

On the other hand, what is this ACL for? split-tunneling or VPN filter? Is the 192.168.1.0/24 network the VPN pool?

Thanks.