cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
0
Helpful
1
Replies

access-list VPN users

e-mourad
Level 1
Level 1

Hi,

Please, can i put an access-list to deny/permit for a such vpn client to access servser. or must i put it on the "ipsec rules".

Ex: access-list outacl permit ip 10.1.198.0 10.1.32.0

vpnpool : 10.1.198.0

servers : 10.1.32.0

thanks

1 Reply 1

ozgur.guler
Level 1
Level 1

you should remove

sysopt connection permit-ipsec

sysopt ipsec pl-compatible

commands for such an access-list to have any effect.