Solved

VPN IPSEC quick question

Posted on 2009-07-14
1
249 Views
Last Modified: 2012-05-07
if I have IPSEC tunnels to and from my sites, do they bypass any ACLs on those sites

ie:
I have 172.16.1.0 and 172.16.2.0. They have a tunnel to themselves over the internet
If I have an ACL on the 172.16.1.0 firewall, that says "deny ip any any" applied to the inside interface, will the tunnel still work?
0
Comment
Question by:WERAracer
1 Comment
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 24852635
With Cisco ASA's the command " sysopt connection permit-ipsec  and sysopt connection permit-vpn " allow packets from an IPsec tunnel  to bypass ACLs on the security appliance.

The tunnels will usually not work without it.  

Here's the reference: http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#Solution12
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
EIGRP Summary 2 33
Regarding command “deactivate snmp traceoptions” in Juniper 3 23
OSPF Cost 2 16
Access List 4 14
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now