Solved

ASA VPN Tunnel access list WARNING

Posted on 2011-09-02
3
1,677 Views
Last Modified: 2012-06-27
I  have a site to site VPN tunnel setup and working between a 5520 and 5505.  However, when locking down the crypto access-list by specific ports, I received the following warning:

WARNING: access-list has port selectors.  This may impact performance.

An example is:
access-list outside_cryptomap ext permit tcp 172.16.0.0 255.255.255.0 host 10.200.0.40 eq 3389

So should I only use ip instead?
access-list permit ip 172.16.0.0 255.255.255.0 host 10.200.0.40

If so, how what is the recommendation on how to lock this down?  Or perhaps I should just ignore the 'This may impact performance' warning?
0
Comment
Question by:B1izzard
  • 2
3 Comments
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
Comment Utility
What you could do is to use only ip on the crypto map list and remove the 'sysopt connection permit-vpn' from your config. After that you must allow vpn traffic by means of an ACE in the outside in access list. Here you should be able to lock it down to port level.
0
 

Author Closing Comment

by:B1izzard
Comment Utility
Thanks.
0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
You're welcome, Thx for the points :)
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
This video discusses moving either the default database or any database to a new volume.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now