cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
911
Views
0
Helpful
2
Replies

IPsec ACL

raza
Level 1
Level 1

My question can we use ip any any in Ipsec point to point or hub spoke enviroment ? if not why?

Regards

2 Replies 2

jzsides
Level 1
Level 1

If you do this all traffic coming in or going out of the interface that the crypto map is applied to, will be included in the VPN. Is this your goal?

Yes this is the case also pls note I have just seen following:

Book "Cisco Secure Pix Firewall Advanced Exam Certification Guide" page 173

"It is not recommended that you use the permit any any command, because it causes all outbound traffic to be encrypted( and all encrypted traffic to be sent to the peer specified in the corresponding crypto map entry), and it requires encryption of all inbound traffic. With they type of access list. The firewall drops all inbound packets that are not encrypted."