Problem solve Get help with specific problems with your technologies, process and projects.

How to restrict traffic between the VPN server and remote Cisco clients

Setting up a VPN tunnel between a Cisco PIX server and remote clients does not always go smoothly. In this expert Q&A, Mike Chapple reviews how careful management of commands and access control lists can successfully restrict user access.

I have recently set up a VPN tunnel between a Cisco PIX 506E (VPN server) and remote clients. Right now, the remote clients have full access to the private network, but I want them to only have access to a specific application. On the Cisco PIX there's also a site-to-site VPN tunnel setup. From what I understand, the command "sysopt connection permit-ipsec," permits IPsec traffic to pass through the PIX firewall without a check of access list command statements. Is it possible to just permit one type of traffic (protocol) to flow between the VPN server and the remote Cisco clients?

You've actually identified your issue in your question. You have the "sysopt connection permit-ipsec" command in...

your configuration. This automatically allows VPN traffic into the internal network without filtering. If you want to apply specific port filters to the tunnel, disable the command and apply an access control list to the appropriate PIX interface. Granted, it's not the easiest thing to configure on a PIX, but it's technically possible.

This was last published in February 2009

Dig Deeper on Integrating security into networks

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.








  • CIO Trends #6: Nordics

    In this e-guide, read how the High North and Baltic Sea collaboration is about to undergo a serious and redefining makeover to ...

  • CIO Trends #6: Middle East

    In this e-guide we look at the role of information technology as the Arabian Gulf commits billions of dollars to building more ...

  • CIO Trends #6: Benelux

    In this e-guide, read about the Netherlands' coalition government's four year plan which includes the term 'cyber' no fewer than ...