cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
848
Views
0
Helpful
5
Replies

How to limit one ip address to have remote access VPN to PIX?

kokkeong-low
Level 1
Level 1

I would like to allow only 1 public ip to have remote access vpn to a PIX 506E,

already remove sysopt connection permit-ipsec.

apply access-list on the outside interface, VPN tunnel still can be establish even if I, apply acl with deny ip any any.

Can any one help?

5 Replies 5

ivillegas
Level 6
Level 6

access list coule be the better option try reconfiguraing the access-list

Hi

In this case the access-list will have no effect,

If you have a router in front of the pix you can do the restrictions there.

regards

Burim

kokkeong-low
Level 1
Level 1

There is no way to do it ?

kokkeong-low
Level 1
Level 1

the problem is this is a broadband connection to isp, the broadband router does not have any firewall capability.

Hi

to make this remote access more secure i would say to you try to implement certificate authentication and aaa, this the best way i think

regards

Burim