CISCO – REMOTE VPN CLIENT ESTABLISHED CONNECTION PORTS

Provide Support for the Cisco VPN Client

On a stateless firewall we need to add a rule-set facing the WAN connection to source port incoming
ipsec ports as no traffic will be inspected.

To provide support for this configuration, create the following protocol definitions:

Note The client computer must be configured as a SecureNat client.

Port number: 500 – IKE
Protocol type: UDP
Direction:  Receive

Port number: 4500 – NAT-T
Protocol type: UDP
Direction:  Receive

ip access-list extended INTERNET
remark REMOTE_VPN_CLIENT
permit udp any eq 500 any
remark NAT-T
permit udp any eq 4500 any
remark ESTABLISHED_TRAFFIC
permit tcp any any gt 1023 established
remark DENY_ALL
deny ip any any log