Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Applying ACL's for remote VPN Clients

Status
Not open for further replies.

mpots

Vendor
May 18, 2004
5
US
Once VPN clients are terminated on the outside interface, will the ACL on the outside interface be applied on unencrypted traffic? I need to deny VPN clients to various services and IP hosts via ACL's. I can do this with AAA, but would like to implement ACLs on either the inside or outside interface.

Is there any documents that describe the order of operations on the PIX for VPN traffic (like outside ACL->VPN tunnel->...)
 
No you can not do it with the interface access lists. Traffic from a tunnel is not checked against the ACL on the interface that it came through. And access lists can not be applied to traffic leaving an interface.
 
I kinda thought so. So RADIUS authentication is the only way it sounds.

Thanks
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top