VPN hub redundancy and load sharing topologies

Last Updated : Nov 06, 2012 |

Traffic direction

ACL parameter

ACL value

Ingress

IKE (UDP/500) from remote tunnel endpoint to local tunnel endpoint

Permit

Ingress

ESP/AH from remote tunnel endpoint to local tunnel endpoint

Permit

Ingress

Allowed ICMP from any IP address to local tunnel endpoint

Permit

Ingress

Default

Deny

Egress

IKE (UDP/500) from local tunnel endpoint to remote tunnel endpoint

Permit

Egress

All allowed services from any local subnet to any IP address

Permit

Egress

Allowed ICMP from local tunnel endpoint to any IP address

Permit

Egress

Default

Deny