ASA VPN Tunnel access list WARNING

B1izzard
B1izzard used Ask the Experts™
on
I  have a site to site VPN tunnel setup and working between a 5520 and 5505.  However, when locking down the crypto access-list by specific ports, I received the following warning:

WARNING: access-list has port selectors.  This may impact performance.

An example is:
access-list outside_cryptomap ext permit tcp 172.16.0.0 255.255.255.0 host 10.200.0.40 eq 3389

So should I only use ip instead?
access-list permit ip 172.16.0.0 255.255.255.0 host 10.200.0.40

If so, how what is the recommendation on how to lock this down?  Or perhaps I should just ignore the 'This may impact performance' warning?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Senior infrastructure engineer
Top Expert 2012
Commented:
What you could do is to use only ip on the crypto map list and remove the 'sysopt connection permit-vpn' from your config. After that you must allow vpn traffic by means of an ACE in the outside in access list. Here you should be able to lock it down to port level.

Author

Commented:
Thanks.
Ernie BeekSenior infrastructure engineer
Top Expert 2012

Commented:
You're welcome, Thx for the points :)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial