Am having a similiar problem here. I find when I apply the dynamic map at
the end of the crypto map that is applied to the interface, the existing
site to site tunnels do not come up.

Haven't had a chance to do any actual diagnostics yet this morning, but was
under the impression it might have something to do with the following
configuration line:

crypto map somemap client configuration address respond

Anyone have any tips?

Cheers,

Nic.

--------------------------------------------
Message: 2
Date: Mon, 07 Jul 2008 12:55:45 -0500
From: "Tolstykh, Andrew" <[EMAIL PROTECTED]>
Subject: Re: [c-nsp] 2800 for VPN Server site-to-site and remote
       access
To: <[EMAIL PROTECTED]>, "'Everton Diniz'" <[EMAIL PROTECTED]>,
       "'cisco-nsp'" <[email protected]>
Message-ID: <[EMAIL PROTECTED]<[EMAIL PROTECTED]>
>
Content-Type: text/plain;       charset="iso-8859-1"

Use multiple statements within a single crypto map configuration:

crypto map iosvpn 5 ipsec-isakmp
 set peer X.X.X.X
 set security-association lifetime seconds 28800
 set transform-set aes-sha
 match address vpn_XXXgard5
 reverse-route
crypto map iosvpn 15 ipsec-isakmp
 set peer X.X.X.X
 set security-association lifetime seconds 28800
 set transform-set aes-sha
 match address vpn_XXXgard15
 reverse-route
crypto map iosvpn 25 ipsec-isakmp
 set peer X.X.X.X
 set security-association lifetime seconds 28800
 set transform-set aes-sha
 match address vpn_XXXgard25
 reverse-route
crypto map iosvpn 35 ipsec-isakmp
 set peer X.X.X.X
 set security-association lifetime seconds 28800
 set transform-set aes-sha
 match address vpn_XXXgard35
 reverse-route
crypto map iosvpn 100 ipsec-isakmp dynamic dyn
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to