Hi team,
while going through lab 2.7 , i noticed that in order to fully meet the requirement of the task of allowing only icmp in the tunnel and applying any related configuration on R1 , the vpn access-group should be applied in the inbound and outbound direction . Cos if any other traffic like telnet is initiated from R1 the vpn filter will not match the traffic.
Rgds