cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
568
Views
2
Helpful
1
Replies

Cisco ASA

cheng.cathy
Level 1
Level 1

thanks

1 Accepted Solution

Accepted Solutions

you can config control-plane ACL as you mention above 
this permit IPsec l2l and anyconnect tcp/443
but for you must consider the direction 
access-list cp-outside permit udp host 125.63.0.0 0.0.255.255 any eq 4500 
access-list cp-outside permit udp  any host 125.63.0.0 0.0.255.255 eq 4500 <<- correct one 

your OUT inteface must receive the traffic from any IP. 
Note:- do same for all  ACL line 


View solution in original post

1 Reply 1

you can config control-plane ACL as you mention above 
this permit IPsec l2l and anyconnect tcp/443
but for you must consider the direction 
access-list cp-outside permit udp host 125.63.0.0 0.0.255.255 any eq 4500 
access-list cp-outside permit udp  any host 125.63.0.0 0.0.255.255 eq 4500 <<- correct one 

your OUT inteface must receive the traffic from any IP. 
Note:- do same for all  ACL line