Hi, On Thu, Mar 11, 2010 at 06:53:46PM +0100, Peter Rathlev wrote: > Yes, and though I would like to use VTI the other end are not able to. > So that's a no go.
This surprises me somewhat. The config variant you use to configure the
IPSEC stuff on your end should be completely transparent to the other
side, as long as the resulting packets match:
- IKE phase 1 + 2 proposals
- IKE phase 2 SA (= with crypto maps: tied to ACL lines)
- protocol stacking (IP-in-GRE-in-IPSEC?)
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
pgpEnUTlW7iNK.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
