cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
469
Views
0
Helpful
2
Replies

ASA for vpn only

johnd2310
Level 8
Level 8

Hi,

I would like to configure the ASA for vpn only. By default ASA allows traffic from high security interface to low security interface. I want to stop this. Is there a way of doing this without resorting to access lists.

thanks

John

**Please rate posts you find helpful**
1 Accepted Solution

Accepted Solutions

Collin Clark
VIP Alumni
VIP Alumni

Set the interfaces to the same security level and make sure you do not have same-security-traffic permit       inter-interface enabled.

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml

Hope that helps.

View solution in original post

2 Replies 2

Collin Clark
VIP Alumni
VIP Alumni

Set the interfaces to the same security level and make sure you do not have same-security-traffic permit       inter-interface enabled.

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml

Hope that helps.

Hi,

Thanks, That helps. I see the implicit rules all all deny when that is done.

Thanks

John

**Please rate posts you find helpful**