Hello Kings, I've configured the "address ipv4" as the physical interface. So it's the same as not configuring it , the multicast rekeys will originate from the physical interface. My rekey ACL did not have a source IP
"permit ip any host 239.1.0.2" I guess it ignores the source section of the REKEY acl? Cheers, TacACK
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
