Sysopt - Can Someone Settle An Argument

I have sysopt connection permit-ipsec on my PIX for VPN users terminating on the outside interface.

I understand that sysopt allows VPN traffic to bypass an access-list when users VPN in (outside interface). Assuming that I also have an inside access-list (assigned of course to the inside interface), does the return traffic bypass the inside access list when returning to the remote host.

I thought not. My colleague says it does.

That aside, has anyone noticed PIX 7.2.X nat (0) access-list entries failing to increment when building VPN's. I seem to have a scenario where my site to site VPN works absolutely fine but my nat (0) doesn't increment.

Regards

Darren

Reply to
Darren Green
Loading thread data ...

Your colleague is correct. The effect of permit-ipsec is bidirectional.

Reply to
Walter Roberson

Thanks Walter. Guess I'll be eating some humble pie.

Reply to
Darren Green

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.