That's where he needs to apply it.  Once the sysopt has been removed, the VPN 
traffic will get checked against the outside inteface ACL.

The crypto map ACL is for the proxies to define which traffic traverses the VPN.
  ----- Original Message ----- 
  From: Mario Spinthiras 
  To: Tony Varriale 
  Cc: [EMAIL PROTECTED] ; Ryan Bradley ; Cisco NSP Forum 
  Sent: Friday, October 24, 2008 3:41 PM
  Subject: Re: [c-nsp] Restric access in a VPN tunnel


  Why cant he leave his acl for the crypto map alone and simply apply the 
relevant access list on the interface to restrict specific entries? Will this 
affect his vpn (don't think so) ?

  Regards,
  Mario
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to