Firewall Wizards mailing list archives

Re: Pass-through VPN


From: Josh Welch <jwelch () buffalowildwings com>
Date: Wed, 06 Oct 2004 22:24:52 -0500



Melson, Paul wrote:

-----Original Message-----
I think that you are referring to something like:

sysopt connection permit-ipsec

Which automatically allows all traffic through VPN tunnels.  However,

if
I understand correctly this does then limit your ability to apply ACLs to VPN traffic.


This option only affects IPSec traffic that is decrypted by the PIX, not
traveling through it.  And then, yes, it bypasses any access-list that
would otherwise apply to said IPSec traffic.

PaulM

Yeah, I misunderstood the original post.
Mea Culpa :)

Josh
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: