08-27-2020 01:46 AM
Hello;
On my Cisco ASA 5516X Firepower (FTD) device, remote Access vpn is running, but I want to set IP filtering to this. Only 1.1.1.1 external IP address should login vpn, how can I set this.
My Remote Access Configuration for remote Access are:
Source Zones Destination Zones Source Network Destination Network
1 OutboundNet InternalNet VPNnetwork InternalNetwork
2 InternalNet OutboundNet InternalNetwork VPNnetwork
Solved! Go to Solution.
08-27-2020 01:51 AM
Hi,
I don't think this is possible on FTD, unless you can configure a control-plane ACL via Flexconfig...this possibly isn't supported by cisco though. You could apply an ACL on the upstream router, permitting/denying the traffic accordingly. Alternatively if you were using a 2FA solution such as Duo that can restrict traffic from source.
HTH
08-27-2020 01:51 AM
Hi,
I don't think this is possible on FTD, unless you can configure a control-plane ACL via Flexconfig...this possibly isn't supported by cisco though. You could apply an ACL on the upstream router, permitting/denying the traffic accordingly. Alternatively if you were using a 2FA solution such as Duo that can restrict traffic from source.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide