cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
395
Views
0
Helpful
1
Replies

Trust IPSec traffic and avoid going through access control lists

costaskyrri
Level 1
Level 1

IS there a command for ios routers like the pix command

--- sysopt connection permit-ipsec---

which will bypass the outside access-lists.

1 Reply 1

aacole
Level 5
Level 5

No, If you have an ACL on an interface you have to permit the IPSec traffic in the list.

Also, if the traffic is decrypted on the router with the ACL, in earlier IOS versions you had to permit the decrypted addresses and protocols in the ACL as well. This feature did change as IOS developed, may be worth researching if your likely to be affected by this.

Andy