cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
477
Views
0
Helpful
1
Replies

VPN pass through and the Self Zone and NAT

Patrick Colbeck
Level 3
Level 3

Hi

If we have a router running zone based firewall and doing NAT but the VPN terminates on a ASA on teh inside zone do we need to consider the incoming client VPNs as being destined for the "self" zone if we are using NAT overloading through the outside interface of the router ?

1 Accepted Solution

Accepted Solutions

andrew.prince
Level 10
Level 10

No

The rules are below:

* Whenever you filter traffic transiting the router, you control it with a zone-pair specifying an inside and an ouside zone.

* The self zone controls traffic sent to the router itself or originated by the router.

* Unless you specify a zone-pair combining self zone with another zone, all traffic from that zone sent to the router itself is allowed (the router is not protected)

* To control traffic that the router can send into a zone use a zone-pair from self to another zone. Use inspect in the service-policy to allow the return traffic.

* To filter the traffic that the router can accept, use a zone-pair from another zone to self. Only the packets accepted by this zone-pair's service-policy will be accepted by the router.

HTH>

View solution in original post

1 Reply 1

andrew.prince
Level 10
Level 10

No

The rules are below:

* Whenever you filter traffic transiting the router, you control it with a zone-pair specifying an inside and an ouside zone.

* The self zone controls traffic sent to the router itself or originated by the router.

* Unless you specify a zone-pair combining self zone with another zone, all traffic from that zone sent to the router itself is allowed (the router is not protected)

* To control traffic that the router can send into a zone use a zone-pair from self to another zone. Use inspect in the service-policy to allow the return traffic.

* To filter the traffic that the router can accept, use a zone-pair from another zone to self. Only the packets accepted by this zone-pair's service-policy will be accepted by the router.

HTH>

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: