Link to home
Start Free TrialLog in
Avatar of eggster34
eggster34

asked on

vpn traffic filtering on site to site VPNs

Hi I have a site to site VPN on an ASA device running OS 8.4
my side of the network is on 192.168.1.0 / 24
the other side of the VPN is 10.0.0.0 / 24
I need to set up a rule so that while I can access all hosts on 10.0.0.0 / 24
none of the hosts on 192.168.1.0 / 24 should be able to access our side of the tunnel.

Is this possible?
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

I think that should be possible. If you have something like sysopt permit-vpn in your config, remove that. After that you need to allow vpn traffic through an ACE on the outside interface just like any other traffic from the outside.
So if you don't add a rule I think it would work like any other traffic through the ASA. From the inside to the outside and return traffic should work.
Avatar of eggster34
eggster34

ASKER

that does not work at all.
Ok,

Could you tell what you did? And could you have a look at the logging to see if anything shows there?
ASKER CERTIFIED SOLUTION
Avatar of V K
V K
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial