05-02-06 06:13 AM
In article <1146524836.593604.149240@g10g2000cwb.googlegroups.com>,
<silviumed@gmail.com> wrote:
>I use a VPN site to site, PIX 515 to PIX 501. The access is 2 ways.
>Could I configure a priority through tunnel? I want to permit the
>access only from PIX 515 to PIX 501 and deny from PIX 501 to 515.
As I answered to your posting in comp.dcom.sys.cisco, you can't do
that -- not unless you are prepared to forgo -all- responses
(e.g., not even allow a TCP SYN ACK get through.)
If you just don't want to be able initiate new connections from
the 501 to the 515, follow the guidelines of my other reply.
[ Post a follow-up to this message ]
|