Firewall Wizards mailing list archives

RE: Pass-through VPN


From: "Fetch, Brandon" <BFetch () texpac com>
Date: Mon, 18 Oct 2004 13:15:44 -0500

To make sure I'm understand this correctly...

PIX terminates a VPN on it's outside interface, or any interface with an
Internet addressable address
With the sysopt command, traffic that passes through that VPN tunnel from
the remote site is not able to be ACL'ed appropriately?

But would it not be ACL'able through it's source/destination components?
Source being the remote site's LAN address, destination being someplace else
behind the PIX.

Just a bit confused on what this command truly limits/enables.


Thanks,
Brandon

-----Original Message-----
From: Josh Welch [mailto:jwelch () buffalowildwings com]
Sent: Wednesday, October 06, 2004 10:25 PM
To: Melson, Paul
Cc: firewall-wizards () honor icsalabs com
Subject: Re: [fw-wiz] Pass-through VPN




Melson, Paul wrote:

-----Original Message-----
I think that you are referring to something like:

sysopt connection permit-ipsec

Which automatically allows all traffic through VPN tunnels.  However,

if 

I understand correctly this does then limit your ability to 
apply ACLs  to VPN traffic.


This option only affects IPSec traffic that is decrypted by the PIX, not
traveling through it.  And then, yes, it bypasses any access-list that
would otherwise apply to said IPSec traffic.

PaulM

Yeah, I misunderstood the original post.
Mea Culpa :)

Josh
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


This message is intended only for the person(s) to which it is addressed 
and may contain privileged, confidential and/or insider information. 
If you have received this communication in error, please notify us 
immediately by replying to the message and deleting it from your computer. 
Any disclosure, copying, distribution, or the taking of any action concerning
the contents of this message and any attachment(s) by anyone other 
than the named recipient(s) is strictly prohibited.

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: