# Unidirectional VPN

**URL:** https://forum.networklessons.com/t/unidirectional-vpn/55469
**Category:** Security
**Created:** [February 16, 2025, 5:38pm UTC](https://forum.networklessons.com/t/unidirectional-vpn/55469 "2025-02-16T17:38:48Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![1130](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/1/13edae/32.png) [@1130](https://forum.networklessons.com/u/1130)
#### Post date: [February 16, 2025, 5:38pm UTC](https://forum.networklessons.com/t/unidirectional-vpn/55469/1 "2025-02-16T17:38:48Z")

</div>

Hi,  
first of all I hope the category of this post is somewhat accurate.  
Now for my question: I would like to establish an ipsec-isakmp based VPN that only works unidirectional. To iplement the unidirectional aspect of the vpn my first thought was to implement an acl that denies anything and a cbac that inspects esp and udp port 500 traffic. Sadly the cbac options for the inspections don’t support such specific needs. Any ideas how i could achieve that?  
Thank you!

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [February 18, 2025, 7:30am UTC](https://forum.networklessons.com/t/unidirectional-vpn/55469/2 "2025-02-18T07:30:53Z")

</div>

Hello Leon

There is no “out of the box” solution for creating a unidirectional IPSec VPN because IPSec inherently requires bidirectional negotiation (IKE/ISAKMP phases) for tunnel establishment. However, there are ways to achieve or “approximate” a unidirectional data flow by carefully controlling which traffic is allowed in each direction. There are several approaches that you can try, and I list some of them below. You will need to see which one fits best with your arrangement, and further explore the details of implementation.

- Use “Interesting Traffic” (Crypto ACL) to Define One-Way Flows

- Use a Tunnel Interface (VTI) With Routing Controls

These are a couple of options that may help you out. Just keep in mind that in order for an IPsec VPN to function, it initially requires bidirectional communication to establish the tunnel itself. Once that’s done you can apply whatever features are necessary to result in your desired behavior. Let us know how you get along so that we can help you further!

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![1130](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/1/13edae/32.png) [@1130](https://forum.networklessons.com/u/1130)
#### Post date: [February 18, 2025, 7:34pm UTC](https://forum.networklessons.com/t/unidirectional-vpn/55469/3 "2025-02-18T19:34:09Z")

</div>

Hi Laz,

thank you very much for your reply, using a VTI worked really well to achieve my desired behaviour. So a VPN needs bedirectioal traffic to be established, but are there actually any options to control which of the peers is allowed to initiate the connection.

I really appreciate your help!

Leon
