cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
561
Views
0
Helpful
1
Replies

C3945 ISR G2 VPN Router

dfranz3434
Level 1
Level 1

I am looking for a guide on how to Harden my VPN router.  Specifically I am looking for what ACL rules I should be applying on my public exposed interface to ensure only L2L and RA VPNs can establish.

Should I only enable the following ports and deny everything else?

  • IP Protocol Type=UDP, UDP Port Number=500
  • IP Protocol Type=UDP, UDP Port Number=4500
  • IP Protocol Type=ESP (value 50)

Any assistance is appreciated.

1 Reply 1

That's correct. For IPSec VPNs you only need IP/50, UDP/500 and UDP/4500.


Sent from Cisco Technical Support iPad App