cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
419
Views
0
Helpful
2
Replies

access-list in VPN

iqbalkhan
Level 1
Level 1

Hi

I want all data when pass through router are encrypt. for this i can put only access-list 0.0.0.0 host 0.0.0.0

it is right or wrong ?.

Thanks

Biplob

2 Replies 2

spremkumar
Level 9
Level 9

Hi

Its not suggested to encrypt all the data which can hog your hardware resources like CPU & Memory.

Better try to encrypt the interesting traffic which can be your business critical application and have an impact on your business.

By encrypting the whole traffic you will end up in encrypting the internet traffic as well as other unecessary traffic which requires no encryption strength at all given to it.

regds

Yes it is not good to encrypt all the traffic. If you still want to do it, make sure your crypto ACL will deny all traffic from the IPsec source to the IPsec peer