This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking UDP 500 to external networks without impacting a site-to-site tunnel

Hello, we’ve had an external PCI compliance scan done on our network. It brought up UDP port 500 being in an open state and visible from external networks. We don’t have any active SSL VPNs besides a site-to-site tunnel going to one of our other branches. 

Is there anyway to configure a rule to block complete external access to port 500 while keeping the communications in tact for the site-to-site tunnel? Our end goal is to ensure that the tunnel is not visible from the outside. We’ve attempted to create a black hole IP address for port 500, however this caused a conflict with our existing tunnel and had to deactivate it.



This thread was automatically locked due to age.

Top Replies

  • Hi,

    please review the log viewer firewall with a filter on UDP 500 to find which firewall rule is allowing the traffic out or in. The rule blocking the traffic will need to be immediately below your rule allowing the traffic.

    Ian

    Jump to answer