Solved

vpn traffic filtering on site to site VPNs

Posted on 2012-03-17
4
577 Views
Last Modified: 2012-08-13
Hi I have a site to site VPN on an ASA device running OS 8.4
my side of the network is on 192.168.1.0 / 24
the other side of the VPN is 10.0.0.0 / 24
I need to set up a rule so that while I can access all hosts on 10.0.0.0 / 24
none of the hosts on 192.168.1.0 / 24 should be able to access our side of the tunnel.

Is this possible?
0
Comment
Question by:eggster34
  • 2
4 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37732400
I think that should be possible. If you have something like sysopt permit-vpn in your config, remove that. After that you need to allow vpn traffic through an ACE on the outside interface just like any other traffic from the outside.
So if you don't add a rule I think it would work like any other traffic through the ASA. From the inside to the outside and return traffic should work.
0
 

Author Comment

by:eggster34
ID: 37735511
that does not work at all.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37735663
Ok,

Could you tell what you did? And could you have a look at the logging to see if anything shows there?
0
 
LVL 6

Accepted Solution

by:
alienXeno earned 500 total points
ID: 37736588
check vpn filters for ASA at
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml

 The vpn-filter is applied to post-decrypted traffic after it exits a tunnel and pre-encrypted traffic before it enters a tunnel.
Exercise caution when you construct the ACLs for use with the vpn-filter feature. The ACLs are constructed with the post-decrypted traffic (inbound VPN traffic) in mind. However, they are also applied to the traffic originated in the opposite direction.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question