Force authentication only on a predefined interface


Is it possible to set up an IPSEC tunnel for a certain group only on a predefined interface? And how?

The isamkp must be enabled on all the interface, because I tunnel on any interface.

Thank you.


Well you can remove the permit-vpn connection systop command and allow only virtual private networks via ACL. This command allows to bypass ACL control for crypto ending traffic by firewall; sound activated by default. Disable this and allow each SPECIFIC IP access to specific crypto interface. Or refuse some and allow others (this would be particularly true outside).

ASA 8.1 added support for netflow but only on models of the upper range (5580-XX). Perhaps we see in the future on other models as well.



  • Problem with IP LRT224 web interface

    I have my LRT224 put in place about a week ago. It works very well for a while, but right now I can only access the web interface through the first LAN. If I use any other LAN and type the IP Address of the gateway on my browser as, the address bar will change to 'https://[::ffff:a06:1501]/' instead, and it displays the page Web is not available.

    I don't know in the parameter 'Port management'-> '802. 1 q"all my Device Management are enabled.

    Anyone know what's the problem?

    I found something, when enable https and IPV6, this problem occurs.

