Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2132
  • Last Modified:

ASA VPN Tunnel access list WARNING

I  have a site to site VPN tunnel setup and working between a 5520 and 5505.  However, when locking down the crypto access-list by specific ports, I received the following warning:

WARNING: access-list has port selectors.  This may impact performance.

An example is:
access-list outside_cryptomap ext permit tcp 172.16.0.0 255.255.255.0 host 10.200.0.40 eq 3389

So should I only use ip instead?
access-list permit ip 172.16.0.0 255.255.255.0 host 10.200.0.40

If so, how what is the recommendation on how to lock this down?  Or perhaps I should just ignore the 'This may impact performance' warning?
0
B1izzard
Asked:
B1izzard
  • 2
1 Solution
 
Ernie BeekExpertCommented:
What you could do is to use only ip on the crypto map list and remove the 'sysopt connection permit-vpn' from your config. After that you must allow vpn traffic by means of an ACE in the outside in access list. Here you should be able to lock it down to port level.
0
 
B1izzardAuthor Commented:
Thanks.
0
 
Ernie BeekExpertCommented:
You're welcome, Thx for the points :)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now