8pcallahan Fri, 10/31/2008 - 09:00
User Badges:

You might consider filtering out the LAN-to-LAN sites in the inspection rule. If you are using static IP addresses with your ISP you may filter further based on those.

Example - In the keyword section of the inspection rule:

Group NOT


%ASA-3-713119: Group = x.x.x.x, IP = x.x.x.x, PHASE 1 COMPLETED)

It can take some real tweaking to get the desired result. Let me know if you need a more specific example of a rule. Hope this helps.

mdreelan Fri, 10/31/2008 - 09:34
User Badges:

good idea...im learning to think a bit more like CSMARS....using "!=" solves more than one isse.


This Discussion