04-28-2009 07:46 AM
Hi,
I have a new ASA and have connected a VPN, it seems to not care about any ACL's I put on then I remember there is a command I can add so VPN's use ACL's, what is this?
Thanks
04-28-2009 01:50 PM
Are you referring to not having to add VPN related protocols to an ingress ACL applied to the outside interface? If so, you are more than likely referring to the "sysopt connection permit-vpn".
05-01-2009 07:32 AM
Right, that is the normal configuration. In 8.x and maybe 7.x there is a command 'vpn-filter' which can be set per group-policy and reference an ACL. That ACL will be imposed on inbound traffic and outbound traffic.
Alternately you have to disable the 'sysopt connection permit-ipsec' (or 'permit-vpn' for 8.x), and then create an ACL that you apply to your outside interface to allow IPSec traffic connections, but filter access to internal systems.
Using the vpn-filter command is MUCH easier though.
05-01-2009 07:39 AM
Thanks, "sysopt connection permit-vpn" was the one I used.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide