cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
804
Views
0
Helpful
3
Replies

IPSec client ACL

cxo-179682
Level 1
Level 1

Hi,

Need to know whether is it possible to define an ACL per group/user basis for IPSec client??

Anyone can provide me some sample or URL??

Thanks.

3 Replies 3

aacole
Level 5
Level 5

Can you redefine your question, what do you want the ACL to do?

sorry for the confusion.

everytime when user logs in using cisco vpn client, they are able to connect to all the server/devices. But i need to restrict them only to connect to one or two servers only.

which mean i need an acl per user/group based on the IPSec connection, but i can't find any of these setting in the box.

hope you understand.

with pix v6.x, the way is to disable the command "sysopt connection permit-ipsec'.

with this command disabled, the crypto traffic will be verified with the inbound acl. in other words, inbound acl for crypto is required.

e.g.

access-list inbound permit tcp host 192.168.1.1 eq 3389

access-list inbound permit tcp host 1921.68.1.2 eq 22

one thing needs to be noticed is that once the remote user has full access to a server, he/she may hop onto other resources on the lan from that particular server.