Is there any way to get the decrypted client traffic to pass through the
access-lists on a pix firewall, everything I found bypasses the
access-lists.
Use the sysopt connection permit-ipsec command in IPSec configurations to
permit IPSec traffic to pass through the PIX Firewall without a check of
conduit or access-list command statements
The sysopt ipsec pl-compatible command allows IPSec packets to bypass the
NAT and ASA features and enables incoming IPSec packets to terminate on the
sending interface.
The sysopt ipsec pl-compatible command is not available on a PIX 501.