Well, it is a bit tricky, one way is to do a split tunnel and only tunnel the ips you want them to be able to reach, another would be disabling "sysopt connection permit-ipsec", this will make the traffic inspected by the outside acl before entering your lan, just remember that you also have to enable udp500/esp from any, since you probably dont know the clients public ips beforehand.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.