Microsoft
Software
Hardware
Network
Question : How to Create a "One Way" VPN in Cisco ASA
Hi All,
I have created an isolated network which I allow access some external parties access.
I have setup a remote access VPN to that network so the external parties can access it freely.
I also have setup a site to site VPN to this network from our corporate network.
This is all working as expected.
Now I wish to deny all traffic through the site-site VPN from from the "Isolated" network to the corporate network while permitting all traffic thorugh the site-site VPN from corporate to the isolated network.
10.10.0.0 ------ Internet ----- 10.12.1.0
Corporate Isolated
I have done the following:
On the corporate ASA:
group-policy FilterToTull internal
group-policy FilterToTull attributes
vpn-filter value blockVSExtlabtoTull
access-list blockVSExtlabtoTull extended deny ip 10.12.1.0 255.255.255.0 any
tunnel-group xx.xx.xx.xx type ipsec-l2l
tunnel-group xx.xx.xx.xx general-attributes
default-group-policy FilterToTull
But this seems to result in a Bi-Directional restriction. I require only a one way block.
Any ideas?
Many thanks,
Shane
Answer : How to Create a "One Way" VPN in Cisco ASA
It does sound a bit messy. I still think the traffic should be blocked at ingress i.e. on the isolated firewall.
Random Solutions
Resetting/Reconfiguring PIX 501 + Physical Connection
unix mail related question
pix to pix vpn question
Restore failing on a NW 5.1 SP5 server using Brightstor Arcserve v. 9
Can a new reverse DNS record break a MX record
Help!!Can not setup VPN with the SONICWALL router
Two Cisco 1200 APs - Trying to setup roaming configuration
SQL Server slow when logged on domain
GSM Modem With Phone
How do I set up a VPN connection that requires an RSA or similar Token