Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Filtering ports in a VPN Client 2

Status
Not open for further replies.

danr19

Technical User
Aug 30, 2003
24
AR
Hi,

Does anybody know how to configure the PIX to limit some ports to the users connected through the VPN with Cisco VPN Client?

Regards,

danr19
 
Disable the sysopt connectio permit-ipsec and configure the corresponding ACL entries on the interface with the crypto map. You will need to also open UDP port 500 and IP protocol 50.
 
Hi,

Thanks for your advice, it has solved my problem and you has won a star.
I didn't have to open UDP 500 and IP 50. I think perhaps I'm using traversal-nat.
After I've read your message, I've found a thread about ACL with VPN started on September 29th (multiple access lists per VPN). It was very clear.
I've already enabled the antispoofing feature on all interfaces.
Do you have any advice or warn?

Thanks,

danr19
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top