Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

State-full firewall issues with VPN client 4.0

Because of the limitations of the PIX I’m utilizing split-tunneling and would like to have the firewall feature enabled on the VPN client. The only problem I have is we have management stations like SMS etc. that need to initiate connections to the VPN client system. Is there anyway to configure the firewall so that all systems within the tunnel are allowed to initiate connections to the VPN client machine but still block everything else?

Thanks in advance for any assistance!

-Jesse

3 REPLIES
New Member

Re: State-full firewall issues with VPN client 4.0

No way to configure it.. Not sure if it is in the works to allow any configuration or not.

http://www.cisco.com/en/US/partner/products/sw/secursw/ps2308/products_user_guide_chapter09186a008015ce82.html#1305900

Stateful Firewall (Always On) provides even tighter security. When enabled, this feature allows no inbound sessions from all networks, regardless of whether a VPN connection is in effect. Also, the firewall is active for both encrypted and unencrypted traffic. There are two exceptions to this rule:

DHCP, which sends requests to the DHCP server out one port but receives responses from DHCP through a different port. For DHCP, the stateful firewall allows inbound traffic.

ESP - The stateful firewall allows ESP traffic from the secure gateway, because ESP rules are packet filters and not session-based filters. For the latest information on other exceptions, if any, refer to Release Notes for Cisco VPN Client for Windows.

New Member

Re: State-full firewall issues with VPN client 4.0

Thank you!

New Member

Re: State-full firewall issues with VPN client 4.0

Hi,

Your answer actually applies to problems we are having here. However when I click the link I don't get anywhere other that the page saying this link has moved, etc. Can you tell me the tittle of the document and I could then search for it. Thanks for your help.

Randy Moore

NOVA Chemicals.

167
Views
0
Helpful
3
Replies
CreatePlease to create content