Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

how do I apply access list to a site to siste vpn between routers

Hi all

I ahve created a vpn tunnel between 2 routers over the internet,

I need an access list whereby I allow the public ip addresses to talk to each other, and also the vpn traffic to come in between the sites

where would I apply the access list for the vpn traffic ?

5 REPLIES
New Member

how do I apply access list to a site to siste vpn between router

Public Interface, define allowed protocols requierd to create tunnel (GRE, IPSEC,) from the public address of the other router.

On the Tunnel interface for site to site (privately addressed machines, assuming you want to control this traffic between sites)

Regards Neil

Regards Neil http://uk.linkedin.com/pub/neil-grant/20/5b0/267
Super Bronze

Re: how do I apply access list to a site to siste vpn between ro

Disclaimer

The  Author of this posting offers the information contained within this  posting without consideration and with the reader's understanding that  there's no implied or expressed suitability or fitness for any purpose.  Information provided is for informational purposes only and should not  be construed as rendering professional advice of any kind. Usage of this  posting's information is solely at reader's own risk.

Liability Disclaimer

In  no event shall Author be liable for any damages whatsoever (including,  without limitation, damages for loss of use, data or profit) arising out  of the use or inability to use the posting's information even if Author  has been advised of the possibility of such damage.

Posting

If you want to "... allow the pubic ip addresses to talk to each other, ...", and as a VPN tunnel is communications between the public IPs, what are you trying to restrict?

If you want to restrict traffic to your router's public IPs, to just the VPN tunnel traffic, you then only allow traffic that appears to be VPN traffic with a destination IP of your public IP.  BTW, this doesn't preclude still allowing transit traffic through the same interface, as such's destination IP shouldn't be your router's public IP; although you can block that traffic too.

New Member

how do I apply access list to a site to siste vpn between router

basically, I want to allow the public ip's on the outside interface, so the vpn will form

then I want to restrict what traffic comes through the site to site vpn tunnel. Obviously the interesting traffic is defined via the access list and crypto map, but it there a way to limit traffic on the vpn side so only allowing certain internal networks to go across it, or is this only done via the acl and crypto map ?

cheers

New Member

how do I apply access list to a site to siste vpn between router

You would need to define only the traffic within the interested list allowed to bring the tunnel up. If it were a GRE based link the you could apply this to the Tunnel interface.

Regards Neil 

http://uk.linkedin.com/pub/neil-grant/20/5b0/267

Regards Neil http://uk.linkedin.com/pub/neil-grant/20/5b0/267
Super Bronze

Re: how do I apply access list to a site to siste vpn between ro

Disclaimer

The   Author of this posting offers the information contained within this   posting without consideration and with the reader's understanding that   there's no implied or expressed suitability or fitness for any purpose.   Information provided is for informational purposes only and should not   be construed as rendering professional advice of any kind. Usage of  this  posting's information is solely at reader's own risk.

Liability Disclaimer

In   no event shall Author be liable for any damages whatsoever (including,   without limitation, damages for loss of use, data or profit) arising  out  of the use or inability to use the posting's information even if  Author  has been advised of the possibility of such damage.

Posting

As also posted by Neil, to control the traffic across the tunnel interface, apply an ACL to the tunnel interface.

To limit physical interface to your VPN, you would apply the ACL to the physical interface.

BTW, if you're equipment supports it, you might consider VTI tunnels rather than GRE/IPSec.  Config is a clearer and eliminates the GRE overhead.

160
Views
0
Helpful
5
Replies