cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
0
Helpful
4
Replies

L2L IPSec Policy based VPN Port Restriction

Praveen Kumar
Level 1
Level 1

We have about 100 VPN tunnels on the FTD managed by FMC.
       > All tunnels are policy based IPSec tunnels
       > All tunnel "End Point" use standard ACL 
       > All tunnels have "sysopt permit-vpn" enabled

Now, we want the newer tunnels to have port level restrictions in addtion to IP. How can this be accomplished? I see  "Access List (Extended)" under "Protected Networks:" but I am not sure if that is the best option. Please advise. 

1 Accepted Solution

Accepted Solutions

@Praveen Kumar ok, I think VPN filters where added to the GUI in 7.1, so you could try deploying using flexconfig or upgrade to 7.2.

View solution in original post

4 Replies 4

Thanks for the quick response. I forgot to mention that our FMC is on version 7.0.6. 

@Praveen Kumar ok, I think VPN filters where added to the GUI in 7.1, so you could try deploying using flexconfig or upgrade to 7.2.

Thanks.