Since VPN is intended for a public network such as the Internet, it is recommended to define an access control list using the ip access-control-list command, to avoid traffic that should not enter the device. You should, therefore, define an ingress access control list that allows only IKE, ESP, and ICMP traffic to enter the device from the public interface. For a configuration example see the access control list in Simple VPN topology – VPN hub and spokes.