VPN
Configuring VPN Passthrough
Cisco ISA500 Series Integrated Security Appliances Administration Guide
336
8
STEP 4
Click
Save
to apply your settings.
STEP 5
By default, the firewall denies access from VPN zone to LAN and voice zones. If
you want to allow L2TP clients to access your default VLAN, you must go to the
Firewall > Access Control > ACL Rules page to manually create a firewall rule as
follows:
Configuring VPN Passthrough
Use the VPN Passthrough page to configure VPN Passthrough to allow VPN traffic
that originates from VPN clients to pass through your security appliance. Use this
feature if there are devices behind your security appliance that need the IPSec
tunnels to be set up independently, such as connecting to another router on the
WAN.
STEP 1
Click
VPN > VPN Passthrough
.
The VPN Passthrough window opens.
STEP 2
Specify the type of traffic that can pass through the security appliance:
Field
Setting
From Zone
VPN
To Zone
LAN
Service
Any
Source Address
l2tp_clients
NOTE:
Choose
Create a new address
from the
drop-down list to create an address object
“l2tp_clients” with the IP address range of L2TP
server’s address pool.
Destination Address
DEFAULT_NETWORK
Schedule
Always on
Match Action
Permit