Cisco Systems Cisco PIX EasyVPN site2site - Restrict traffic

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Cisco PIX EasyVPN site2site - Restrict traffic nicough 12-06-06
Posted by on December 6, 2006, 6:33 am
Please log in for more thread options
Hi everyone.

I have set up the HeadOffice PIX 506E as an EasyVPN Server, config
below.
The RemoteOffice PIX 501 successfuly establishes a VPN connection to
the HeadOffice PIX 506E, and communicates.

The question is, how can I restrict traffic between the networks?

Between the two LAN's, I would like to:
Allow anywhere: dns, rdp3389, ntp, icmp
Allow http from 192.168.1.x to 192.168.10.4
Block all smtp
Block rdp3389 from 192.168.1.x to 192.168.10.5

I am unsure how to order this accesslist, and how to link it into the
PIX 506E config.
I requrie that all of these rules be applied to the HeadOffice PIX506E
(rather than the RemoteOffice PIX501) because the RemoteOffice's will
be scattered around the country and I want to keep them as simple as
possible.

Also, am I correct in saying that once the VPN is established, the
RemoteOffice can connect to the HeadOffice, but HeadOffice can NOT
connect to the RemoteOffice?

Also, is it ok having the following two lines saying "30" and "40"
rather than "10" how they were? I'm not sure if these numbers need to
map to each other, or whether they are just a priority number.
crypto dynamic-map dynmap 40 set transform-set myset
crypto map mymap 30 ipsec-isakmp dynamic dynmap

Any help greatly appreciated.
Nick

Internet
/ \
111.111.111.111 Dynamic Internet IP
ADSL Router ADSL Router
10.0.0.254 192.168.88.254
| |
10.0.0.1 192.168.88.1
PIX 506E PIX 501
192.168.10.254 192.168.1.1
| |
HeadOffice LAN RemoteOffice LAN


PIX Version 6.3(5)
hostname HeadOffice
access-list 101 permit ip 192.168.10.0 255.255.255.0 192.168.1.0
255.255.255.0
access-list nonat permit ip 192.168.10.0 255.255.255.0 192.168.1.0
255.255.255.0

ip local pool ippool 172.17.1.1-172.17.1.254
global (outside) 1 interface
nat (inside) 0 access-list nonat
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
route outside 0.0.0.0 0.0.0.0 10.0.0.254 1

sysopt connection permit-ipsec
crypto ipsec transform-set myset esp-aes esp-md5-hmac
crypto dynamic-map dynmap 40 set transform-set myset
crypto map mymap 30 ipsec-isakmp dynamic dynmap
crypto map mymap interface outside

isakmp enable outside
isakmp identity address
isakmp nat-traversal 20
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption aes
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 3600

vpngroup MYGROUP address-pool ippool
vpngroup MYGROUP split-tunnel 101
vpngroup MYGROUP idle-time 1800
vpngroup MYGROUP password MyPassword

______

PIX Version 6.3(5)
hostname RemoteOffice
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
route outside 0.0.0.0 0.0.0.0 192.168.88.254 1
sysopt connection permit-ipsec
vpnclient server 111.111.111.111
vpnclient mode network-extension-mode
vpnclient vpngroup MYGROUP password MyPassword
vpnclient enable


Similar ThreadsPosted
Cisco PIX EasyVPN site2site - Restrict traffic December 6, 2006, 6:33 am
restrict PC traffic speed on the lan August 10, 2008, 1:11 pm
How-to restrict traffic exiting VPN tunnel to certain hosts / ports ?? June 30, 2009, 4:48 pm
EasyVPN with only one address in the pool April 29, 2009, 2:30 am
site2site ipsec with nat December 19, 2005, 11:31 am
Restrict access to Cisco device November 7, 2006, 2:42 pm
Cannot make head or tail of dial watcher is there anothe option to restrict hours Cisco 801 June 21, 2005, 5:22 pm
Restrict By MAC address July 12, 2005, 6:29 pm
PIX - restrict services September 21, 2006, 2:24 am
restrict from designated MAC address January 11, 2006, 11:58 pm
Restrict "sho mon" to enabled level access... June 1, 2007, 8:18 pm
Is there a way to restrict IOS ssh server to only accept certain ciphers? April 17, 2008, 3:17 pm
restrict port connections on switch for known hosts only June 16, 2006, 8:30 am
How does typical ISP traffic shaping/bandwidth limiting work ? Do ISP's allow bursty traffic per second ? January 19, 2006, 3:50 pm
Cisco 2970 strange traffic problem - stumped cisco support February 10, 2005, 12:19 pm
Residential Cabling Guide

Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Learn More