Firewall Wizards mailing list archives
RE: Pass-through VPN
From: "Fetch, Brandon" <BFetch () texpac com>
Date: Mon, 18 Oct 2004 13:15:44 -0500
To make sure I'm understand this correctly... PIX terminates a VPN on it's outside interface, or any interface with an Internet addressable address With the sysopt command, traffic that passes through that VPN tunnel from the remote site is not able to be ACL'ed appropriately? But would it not be ACL'able through it's source/destination components? Source being the remote site's LAN address, destination being someplace else behind the PIX. Just a bit confused on what this command truly limits/enables. Thanks, Brandon -----Original Message----- From: Josh Welch [mailto:jwelch () buffalowildwings com] Sent: Wednesday, October 06, 2004 10:25 PM To: Melson, Paul Cc: firewall-wizards () honor icsalabs com Subject: Re: [fw-wiz] Pass-through VPN Melson, Paul wrote:
-----Original Message----- I think that you are referring to something like: sysopt connection permit-ipsec Which automatically allows all traffic through VPN tunnels. However,ifI understand correctly this does then limit your ability to apply ACLs to VPN traffic.This option only affects IPSec traffic that is decrypted by the PIX, not traveling through it. And then, yes, it bypasses any access-list that would otherwise apply to said IPSec traffic. PaulM
Yeah, I misunderstood the original post. Mea Culpa :) Josh _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards This message is intended only for the person(s) to which it is addressed and may contain privileged, confidential and/or insider information. If you have received this communication in error, please notify us immediately by replying to the message and deleting it from your computer. Any disclosure, copying, distribution, or the taking of any action concerning the contents of this message and any attachment(s) by anyone other than the named recipient(s) is strictly prohibited. _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- RE: Pass-through VPN Melson, Paul (Oct 01)
- Re: Pass-through VPN Josh Welch (Oct 11)
- <Possible follow-ups>
- RE: Pass-through VPN Fetch, Brandon (Oct 22)
- RE: Pass-through VPN Catalina Scott Contr AFCA/EVEO (Oct 22)
- RE: Pass-through VPN Hughes, Chris (Oct 25)
- Re: Pass-through VPN Patrick M. Hausen (Oct 26)
- RE: Pass-through VPN Catalina Scott Contr AFCA/EVEO (Oct 26)