01-29-2009 02:34 AM - edited 03-06-2019 03:44 AM
Hi. How could I enable or disable protocol filtering in a router? If for example I wish to disable vpn esp protocol 500, what is the syntax?
Thanks in advance.
01-29-2009 11:09 AM
Hi Mark,
You can use access-lists for protocol filtering.
For blocking IPsec vpn traffic it may look like this:
access-list 100 deny udp any 500 any 500
access-list 100 deny esp any any
access-list 100 permit ip any any
The 1st line blocks any isakmp traffic.
The 2nd line blocks any ipsec esp protocol traffic.
The 3rd line allows any other ip traffic.
Cheers:
Istvan
01-29-2009 02:22 PM
Hi Mark,
Sorry, probably I was sleeping when I posted my previous message :).
The fist line should be like this:
access-list 100 deny udp any eq 500 any eq 500
or
access-list 100 deny udp any eq isakmp any eq isakmp
Thanks:
Istvan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide