Hi, On Fri, Dec 17, 2010 at 03:33:30PM +0300, Righa Shake wrote: > crypto map MYCRYPTOMAP 10 ipsec-isakmp > set peer X.X.X.X > set transform-set MYCRYPTO1 > match address VPNTRAFF > crypto map MYCRYPTOMAP 20 ipsec-isakmp > set peer Y.Y.Y.Y > set transform-set MYCRYPTO2 > match address VPNTRAFF > crypto map MYCRYPTOMAP 30 ipsec-isakmp > set peer Z.Z.Z.Z > set transform-set MYCRYPTO2 > match address VPNTRAFF
Since the "match address" block is the same, there's no reason why the
router should establish SAs to Y and Z.
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
pgpC4XGeKLDye.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
