cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2146
Views
0
Helpful
3
Replies

VPN PORTS TO OPEN OUTBOUND

ericohermoso
Level 1
Level 1

Hello,

I have a task to open VPN ports outbound only. Please help me on how to configure the firewall to access VPN. I want to open ports of VPN only where will I apply the ports in the firewall.

thank you and best regards

Edwin

3 Replies 3

Marcin Latosiewicz
Cisco Employee
Cisco Employee

I understand that you mean IPsec VPN? And not ANY kind of VPN?

Here's a list.

udp/500 - IKE

udp/4500 - IKE NAT-T

ESP

AH

(IPsec over TCP can use on top a verity of ports ... usually tcp/10000)

Thank you for the reply. I am not so good about VPN. An Application for remote access vpn as configured in firewall, I'm not sure if it is IPSEC VPN. I will try to open this two port, Anyway, Please, what is equivalent port number of esp and AH.

thank you and best regards,

Edwin

Edwin,

ESP and AH are IP protocols.

http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xml

numbers 50 and 51.

Cisco ACLs (both ASA and IOS) allow you to do access-list XYZ permit esp h A h B (same for AH, and it does not require "host", it can be whole subnet).

Marcin

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: