Hello, everybody!
There is PIX525 with dynamic VPN connections for mobile clients. Dynamic crypto map is used. IP-addresses from local pool, authentication throuth radius server with downloading ACL per user. Work normally.
Task: add peer-to-peer IPSEC tunnel to remote client with all security rules.
I see such hole in security and don't know how it close. If on remote side of peer-to-peer tunnel client use ip-addres from my pool for dynamic VPN, he able to connect to any my inside resources throuth dynamic crypto map, because authentication passed with pre-shared key and ACL for dynamic VPN is include local pool addresses and passed too.
How to fix this hole?
Suggest me, please!