RE: [fw-wiz] Pass-through VPN

From: Fetch, Brandon (BFetch_at_texpac.com)
Date: 10/18/04

  • Next message: avraham shir-el (arthur sherman): "[fw-wiz] checkpoint problems w/ linux rpc"
    To: firewall-wizards@honor.icsalabs.com
    Date: Mon, 18 Oct 2004 13:15:44 -0500
    
    

    To make sure I'm understand this correctly...

    PIX terminates a VPN on it's outside interface, or any interface with an
    Internet addressable address
    With the sysopt command, traffic that passes through that VPN tunnel from
    the remote site is not able to be ACL'ed appropriately?

    But would it not be ACL'able through it's source/destination components?
    Source being the remote site's LAN address, destination being someplace else
    behind the PIX.

    Just a bit confused on what this command truly limits/enables.

    Thanks,
    Brandon

    -----Original Message-----
    From: Josh Welch [mailto:jwelch@buffalowildwings.com]
    Sent: Wednesday, October 06, 2004 10:25 PM
    To: Melson, Paul
    Cc: firewall-wizards@honor.icsalabs.com
    Subject: Re: [fw-wiz] Pass-through VPN

    Melson, Paul wrote:
    >
    >>-----Original Message-----
    >>I think that you are referring to something like:
    >>
    >>sysopt connection permit-ipsec
    >>
    >>Which automatically allows all traffic through VPN tunnels. However,
    >
    > if
    >
    >>I understand correctly this does then limit your ability to
    >>apply ACLs to VPN traffic.
    >
    >
    > This option only affects IPSec traffic that is decrypted by the PIX, not
    > traveling through it. And then, yes, it bypasses any access-list that
    > would otherwise apply to said IPSec traffic.
    >
    > PaulM

    Yeah, I misunderstood the original post.
    Mea Culpa :)

    Josh
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    This message is intended only for the person(s) to which it is addressed
    and may contain privileged, confidential and/or insider information.
    If you have received this communication in error, please notify us
    immediately by replying to the message and deleting it from your computer.
    Any disclosure, copying, distribution, or the taking of any action concerning
    the contents of this message and any attachment(s) by anyone other
    than the named recipient(s) is strictly prohibited.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: avraham shir-el (arthur sherman): "[fw-wiz] checkpoint problems w/ linux rpc"

    Relevant Pages

    • Re: Surfing the internet WHILST using a VPN connection (PIX 513)
      ... I don't have any experience with the Cisco VPN client, ... Once on the network users wish to browse the internet. ... There is a PIX 515, and a re-spun version of that called the PIX 515E. ... a seperate physical interface that is also connected to the ISP. ...
      (comp.dcom.sys.cisco)
    • Re: Pix and VPN 3030 traffic routing / redirection
      ... > Currently I have a Pix 515 serving as both a firewall and a VPN ... > Pix dmz interface network: ...
      (comp.security.firewalls)
    • Re: access-list stops telnet
      ... This office has a s2s VPN to 10.10.0.0. ... there are cases that are certain not to work, and there are lurking PIX ... If you want to be able to telnet to a remote PIX itself, ... ssh is permitted to the outside interface of a PIX. ...
      (comp.dcom.sys.cisco)
    • RE: [fw-wiz] Pix VPN endpoint and split-tunnel
      ... Its much cheaper than an ASA, can hang off another interface, etc. ... > Another reply I got here from Simon expressed the possibility that PIX ... PIX 7.0 supports hub and spoke VPN routing, but only hub and spoke; ... > of anything the PIX or VPN client do. ...
      (Firewall-Wizards)
    • Re: pix 501 as vpn server
      ... I have the outside interface with dhcp and the inside is ... :> to properly configure this as VPN with RADIUS. ... over 2 megabits per second of 3DES. ... PIX models support. ...
      (comp.dcom.sys.cisco)