cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
523
Views
0
Helpful
1
Replies

Site-to-Site IPsec VPN & Outside ACL

AJAZ NAWAZ
Level 5
Level 5

Order of operation qtn.

When ipsec is terminated on an ISR for site-to-site vpn, is the acl bound to the outside interface invoked before crypto acl or after?

thanks

1 Reply 1

Collin Clark
VIP Alumni
VIP Alumni

The crypto ACL is not associated with the outside interface, so the ACL on the interface is filters first.