Yes, use subinterfaces:
interface GigabitEthernet0/0.1
interface GigabitEthernet0/0.2
interface GigabitEthernet0/0.3
++

Then attach different crypto-map per sub-interface.  We are doing this.

Regards,
Ge Moua | Email: [EMAIL PROTECTED]

Network Design Engineer
University of Minnesota | Networking & Telecommunications Services
 
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Everton Diniz
Sent: Monday, July 07, 2008 9:46 AM
To: cisco-nsp
Subject: [c-nsp] 2800 for VPN Server site-to-site and remote access

Hi all,

Is it possible to use 2821 for vpn concentrator doing both site-to-site and
remote access connections in only one interface?

Hi have 2 crypto map“s, but the interface accept only one.

crypto dynamic-map vpnmap 10
 set transform-set transfervpn
 reverse-route

crypto map L2L 11 ipsec-isakmp
 set peer 200.200.200.1
 set peer 200.200.201.1
 set transform-set L2L
 match address 120

interface GigabitEthernet0/0
 ip address 200.100.100.1 255.255.254.0
 duplex auto
 speed auto
 crypto map onsaescom
end

Anybody use the 2800 for this purpose?

Tks all.
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to