Am having a similiar problem here. I find when I apply the dynamic map at
the end of the crypto map that is applied to the interface, the existing
site to site tunnels do not come up.
Haven't had a chance to do any actual diagnostics yet this morning, but was
under the impression it might have something to do with the following
configuration line:
crypto map somemap client configuration address respond
Anyone have any tips?
Cheers,
Nic.
--------------------------------------------
Message: 2
Date: Mon, 07 Jul 2008 12:55:45 -0500
From: "Tolstykh, Andrew" <[EMAIL PROTECTED]>
Subject: Re: [c-nsp] 2800 for VPN Server site-to-site and remote
access
To: <[EMAIL PROTECTED]>, "'Everton Diniz'" <[EMAIL PROTECTED]>,
"'cisco-nsp'" <[email protected]>
Message-ID: <[EMAIL PROTECTED]<[EMAIL PROTECTED]>
>
Content-Type: text/plain; charset="iso-8859-1"
Use multiple statements within a single crypto map configuration:
crypto map iosvpn 5 ipsec-isakmp
set peer X.X.X.X
set security-association lifetime seconds 28800
set transform-set aes-sha
match address vpn_XXXgard5
reverse-route
crypto map iosvpn 15 ipsec-isakmp
set peer X.X.X.X
set security-association lifetime seconds 28800
set transform-set aes-sha
match address vpn_XXXgard15
reverse-route
crypto map iosvpn 25 ipsec-isakmp
set peer X.X.X.X
set security-association lifetime seconds 28800
set transform-set aes-sha
match address vpn_XXXgard25
reverse-route
crypto map iosvpn 35 ipsec-isakmp
set peer X.X.X.X
set security-association lifetime seconds 28800
set transform-set aes-sha
match address vpn_XXXgard35
reverse-route
crypto map iosvpn 100 ipsec-isakmp dynamic dyn
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/