cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
186
Views
0
Helpful
2
Replies

Apply blocl in VPN L2L IPsec

Alex Ribas
Beginner
Beginner

Hi all

Hi have on IPsec tunnel with customer.

My Network 10.29.0.0/16

Customer 10.16.0.0/16

access-list 112 line 1 extended permit ip 10.29.0.0 255.255.0.0 10.16.0.0 255.255.0.0
 
The ACL 112  I user to crypto in Tunnel.
 
VPN it's working bidireccional.
But I need block the customer access my Network like TCP ping etc.
Example.
NET: 10.16.0.0 255.255.0.0  cannot PING or TCP in port 22 etc.

How can I do this?
Any clue?
Thank you
Alex
 
2 Replies 2

Rob Ingram
VIP Expert VIP Expert
VIP Expert

@Alex Ribas what device is this, a router or ASA?

If router, apply an interface ACL, explictly deny the traffic you want to deny then permit the rest.

If ASA, you can apply a VPN filter to the specific VPN tunnel.

if ASA 
https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/99103-pix-asa-vpn-filter.html

if Router
set ip access-group {access-list-number | access-list-name} {in | out}

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers