From: Richard Dumoulin (richard.dumoulin@vanco.es)
Date: Wed Mar 17 2004 - 11:13:39 GMT-3
Hi all,
I have a question about security. Suppose we have a Hub router that is
receiving dynamic IPSec tunnels from several remote routers. I thought that
only allowing isakmp, esp and ahp in an acl would suffice to secure the
router but I have noticed that first the acl is checked and then the
encryption is done. Does this mean that an acl statement should be done for
every user application inside the tunnels ?
Thx
--Richard
This archive was generated by hypermail 2.1.4 : Thu Apr 01 2004 - 08:15:32 GMT-3