cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
397
Views
0
Helpful
1
Replies

Dial-up VPN security

4mkopser
Level 1
Level 1

I would think there would be examples of this out there, but I haven't been able to find them if they do exist.

I have a 2610XM that creates a secure tunnel over a dial-up connection with a W2K machine running Cisco's VPN client. My problem is this: Traffic to the internal network does not *have* to be encrypted. Users can disconnect the VPN if they choose to press buttons.

I tried creating an ACL and adding it to the crypto map with a "match address" (see attachment) but all I've managed to do is prevent the VPN from being established.

The attachment includes the IPSEC debug comment and the running config.

TIA,

Martin

1 Reply 1

pradeepde
Level 5
Level 5

According to your access-list, you seem to have encrypting traffic between your inside and encryped and unencrypted networks. ACL 187 permits all traffic between 10.0.8.0 and 10.0.70.0/10.0.77.0.

May be you need to modify them to exclude the traffic that you do not want to encrypt and include only those traffic you wish to encrypt in the ACL 187.