RE: [fw-wiz] Pass-through VPN

From: Catalina Scott Contr AFCA/EVEO (scott.catalina_at_scott.af.mil)
Date: 10/22/04

  • Next message: Paul D. Robertson: "Re: [fw-wiz] Increase in SSH Probing"
    To: "Fetch, Brandon" <BFetch@texpac.com>, <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 22 Oct 2004 11:49:07 -0500
    
    

    Inbound traffic normally requires an access-list or conduit statement to
    allow it to pass.

    But by using the sysopt connection permit-ipsec command, the inbound
    ipsec traffic bypasses all access-lists and counduits.

    Since you can't block inbound traffic on the internal interface as you
    can with a cisco router, the traffic cannot be filtered at this point.

    To lock this traffic down, use ACLs without using the sysopt command.

    -Scott

    -----Original Message-----
    From: Fetch, Brandon [mailto:BFetch@texpac.com]
    Sent: Monday, October 18, 2004 1:16 PM
    To: firewall-wizards@honor.icsalabs.com
    Subject: RE: [fw-wiz] Pass-through VPN

    To make sure I'm understand this correctly...

    PIX terminates a VPN on it's outside interface, or any interface with an
    Internet addressable address With the sysopt command, traffic that
    passes through that VPN tunnel from the remote site is not able to be
    ACL'ed appropriately?

    But would it not be ACL'able through it's source/destination components?
    Source being the remote site's LAN address, destination being someplace
    else behind the PIX.

    Just a bit confused on what this command truly limits/enables.

    Thanks,
    Brandon

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "Re: [fw-wiz] Increase in SSH Probing"

    Relevant Pages

    • Re: Sysopt
      ... > Note The sysopt ipsec pl-compatible command is deprecated. ... > dynamic-map match-address statement. ...
      (comp.dcom.sys.cisco)
    • Re: Easiest/quickest method for very simple interfaces?
      ... > Michael speaks truth here wrt vim. ... >> thought on handling the interface. ... fool-proof switches instead of a single command line interface. ... I meant offering choices ...
      (comp.os.linux.misc)
    • Re: The Linux Revolution: What Happened?
      ... >> with a good graphic interface. ... even the text command is an ... And these simple commands can be made even more accessible through a GUI, ... > image from camera", but I didn't see the point at all, it was much ...
      (comp.os.linux.misc)
    • Re: The Linux Revolution: What Happened?
      ... >> with a good graphic interface. ... even the text command is an ... And these simple commands can be made even more accessible through a GUI, ... > image from camera", but I didn't see the point at all, it was much ...
      (alt.os.linux)
    • Re: The Linux Revolution: What Happened?
      ... > with a good graphic interface. ... even the text command is an ... from camera; start image viewer" or "copy images from camera to disk; ... photoshop, asks fotoshop to resize the photo, and sends it. ...
      (comp.os.linux.misc)