08-12-2008 08:02 AM - edited 02-21-2020 03:53 PM
I'm trying to build site to site vpn using two 5520s. Two ASAs are sitting behind edge Cisco routers. To allow ASAs have site to site VPN, what port do I have to allow on the router to pass VPN traffic? I have to allow remote FW IP to connect to local FW IP. Port 50,51 and 500?
Thanks.
Solved! Go to Solution.
08-12-2008 10:42 AM
08-12-2008 09:38 AM
Yes, you got them all: IP ports 50 and 51 and UDP port 500. Also leave the ICMP ports opened between the IPs for the PathMTU Dicovery.
Please rate if this helped.
Regards,
Daniel
08-12-2008 10:02 AM
Careful not to get mixed up by ports 50 and 51 and ip protocols 50 and 51. You need ip protocol 50(esp) and udp port 500.
08-12-2008 10:12 AM
So, I need access-list setup on the router to allow udp port 500 and ip protocol 50.
Did I get this right?
Thanks.
08-12-2008 10:42 AM
Yes.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide