That's where he needs to apply it. Once the sysopt has been removed, the VPN traffic will get checked against the outside inteface ACL.
The crypto map ACL is for the proxies to define which traffic traverses the VPN. ----- Original Message ----- From: Mario Spinthiras To: Tony Varriale Cc: [EMAIL PROTECTED] ; Ryan Bradley ; Cisco NSP Forum Sent: Friday, October 24, 2008 3:41 PM Subject: Re: [c-nsp] Restric access in a VPN tunnel Why cant he leave his acl for the crypto map alone and simply apply the relevant access list on the interface to restrict specific entries? Will this affect his vpn (don't think so) ? Regards, Mario _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
