Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

IPSec client ACL

Hi,

Need to know whether is it possible to define an ACL per group/user basis for IPSec client??

Anyone can provide me some sample or URL??

Thanks.

3 REPLIES
Silver

Re: IPSec client ACL

Can you redefine your question, what do you want the ACL to do?

New Member

Re: IPSec client ACL

sorry for the confusion.

everytime when user logs in using cisco vpn client, they are able to connect to all the server/devices. But i need to restrict them only to connect to one or two servers only.

which mean i need an acl per user/group based on the IPSec connection, but i can't find any of these setting in the box.

hope you understand.

Gold

Re: IPSec client ACL

with pix v6.x, the way is to disable the command "sysopt connection permit-ipsec'.

with this command disabled, the crypto traffic will be verified with the inbound acl. in other words, inbound acl for crypto is required.

e.g.

access-list inbound permit tcp host 192.168.1.1 eq 3389

access-list inbound permit tcp host 1921.68.1.2 eq 22

one thing needs to be noticed is that once the remote user has full access to a server, he/she may hop onto other resources on the lan from that particular server.

305
Views
0
Helpful
3
Replies
CreatePlease to create content