Firewall Wizards mailing list archives

RE: Pass-through VPN


From: "Melson, Paul" <PMelson () sequoianet com>
Date: Fri, 1 Oct 2004 08:20:42 -0400



-----Original Message-----
I think that you are referring to something like:

sysopt connection permit-ipsec

Which automatically allows all traffic through VPN tunnels.  However,
if 
I understand correctly this does then limit your ability to 
apply ACLs  to VPN traffic.

This option only affects IPSec traffic that is decrypted by the PIX, not
traveling through it.  And then, yes, it bypasses any access-list that
would otherwise apply to said IPSec traffic.

PaulM
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: