cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
284
Views
0
Helpful
1
Replies

Match IPSec packets

carlosv
Level 1
Level 1

Hi,

I need to mark IPSec packets coming from our Firewalls (Checkpoint). We are doing IPSec VPN's between the Firewalls NOT THE ROUTERS in a topology like this:

LAN1--FW1--Router1----WAN-----Router2-FW2--LAN2

Since encryption is already done, how do I match this packets using access-list on the routers? Would match protocol 500 be enough?

Thanks in advance

Carlos

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

You have also posted exactly the same question on the forum for Service Providers/VPN Service Architecture. See my answer to your question in that forum.

HTH

Rick

HTH

Rick