PIX515, v 7.2(2) - only allow specific TCP ports within IPSEC SIte to Site

Unanswered Question
Sep 20th, 2007
User Badges:

I have created a site to site tunnel between two organizations. Org A wants to limit Org B to specific TCP ports on the destination hosts. Can this be done on the Org A PIX? I believe I could limit it by changing the cryptomap ACL on the Org B PIX, but then Org A does not control the access in.

Any suggestions appreciated.


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
rajbhatt Thu, 09/20/2007 - 03:11
User Badges:


In org A crypto map you could specify the source and the destination ports that u would allow for access from org B in the crypto ACL .

For example :

access-list ACL extended permit tcp host eq 8888 host

(this will allow inbound access from org B to org A on port 8888 only )

access-list ACL extended permit tcp host host eq 80 (outbound access to org b only on port 80)



This Discussion