Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

ASA rule to not bypas ACL's over VPN

Hi,

I have a new ASA and have connected a VPN, it seems to not care about any ACL's I put on then I remember there is a command I can add so VPN's use ACL's, what is this?

Thanks

3 REPLIES

Re: ASA rule to not bypas ACL's over VPN

Are you referring to not having to add VPN related protocols to an ingress ACL applied to the outside interface? If so, you are more than likely referring to the "sysopt connection permit-vpn".

New Member

Re: ASA rule to not bypas ACL's over VPN

Right, that is the normal configuration. In 8.x and maybe 7.x there is a command 'vpn-filter' which can be set per group-policy and reference an ACL. That ACL will be imposed on inbound traffic and outbound traffic.

Alternately you have to disable the 'sysopt connection permit-ipsec' (or 'permit-vpn' for 8.x), and then create an ACL that you apply to your outside interface to allow IPSec traffic connections, but filter access to internal systems.

Using the vpn-filter command is MUCH easier though.

New Member

Re: ASA rule to not bypas ACL's over VPN

Thanks, "sysopt connection permit-vpn" was the one I used.

154
Views
0
Helpful
3
Replies
CreatePlease to create content