Lan-to-Lan VPN - Access to certain ports only

Unanswered Question
Mar 1st, 2010

Hi, I'm trying to configure a LAN-to-LAN VPN on a Cisco VPN 3020, I need to configure it so that the access to the local and remote networks is restricted to 3389 only when Phase 2 is negotiated, e.g Source (Local network) Dest (Remote Network) tcp 3389.

I believe this need to be setup via filters but can't find any similar configuration examples, has anyone configured a similar set up or can confirm the correct was this should be configured?

Many Thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
contech-nelsong Mon, 03/01/2010 - 11:09

I believe what you want to do is create rules, which can then be applied to filters, which can in turn be applied to groups. If you only have one group then the filter is applied to the base group.

The rules are fairly straight forward, set source & destination IPs and ports then tell the system to drop or forward matches to that rule.

Rules configuration is accessed through policy management, then traffic management in the submenu.

the 3 steps are

create rules

create filters, apply rules to filters

apply filters to groups.

martin.j.davies... Mon, 03/01/2010 - 13:29

That's great I'll give it go, do you know if the filters are used during phase 2 negotiation?  The  issues i have is a 3rd Party Firewall, the remote end of the VPN, has the local/remote networks ties down to a port and phase 2 is failing because of this so I need to ensure they're being sent during phase 2 negotiations.

Thanks for your reply.

contech-nelsong Mon, 03/01/2010 - 13:38

Honestly, I don;t think so. I think the rules and filters as I have described them to you will work as an ACL applied to a proxy ID of

I've never tried it the way you're suggesting, but there is an option in the rules where instead of 'drop' or 'pass' you can use apply IPSec.

I think that's your best bet.

Have the far end set up logging or debug when you try to connect and they should be able to tell you what proxy ID you are supplying when you try to connect, which will in turn tell you if you're on the right track.

You may even be able to tell from the logging on the 3020 as well, so it's worth looking there too.

martin.j.davies... Wed, 03/03/2010 - 01:45

I've tried applying the filter and the VPN still won't come up, it fails at phase two still, with the port blocking removed at the remote end it works ok.  Anyone know of any cisco docs which advise if this is supported or not?

contech-nelsong Wed, 03/03/2010 - 06:00

Have a look at this page:

It may not describe exactly what you are doing, but it has a good troubleshooting section and describes how you can turn on debugging for IKE on the concentrator. This *should* help you to isolate exactly what is causing the failure.

Post the debug results you get.


This Discussion