Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [Config] Configuring More Than 1 VPN Tunnel (871w)
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Cisco VPN Dialer woes with consumer WAPS »
« Beware the hardware upgrade...  
AuthorAll Replies


MSN

join:2004-05-15
Osgoode, ON

reply to TomS_
Re: [Config] Configuring More Than 1 VPN Tunnel (871w)

This was all good advice. I talked to DocLarge last night and we sorted it out. I teach this stuff for Cisco and he and I arrived at a good analogy:

Essentially the crypto map is a virtual IPsec interface. All VPNs (both site-to-site and remote access) terminate on this virtual interface. If you think of the crypto map as the hub in a hub-and-spoke arrangement with the spokes being the VPN peers this makes sense. In the example above (thanks TomS_ !) the IPsec interface is identified as "ipsec-maps" The different VPN "spokes" are identified by their numbers. For example, "crypto map ipsec-maps 30 ipsec-isakmp" creates "spoke" 30, and the different components of the IPsec policy for moving traffic to/from the peer are grouped by that number:

The key, then, is remembering that you only have one IPsec interface tied to any one physical interface. Once you have created this crypto map, you link it to a "reall" interface like this:

In TomS_ 's config it is done with this command:

/Eric

DocLarge
Premium
join:2004-09-08


4 edits
Thanks for the replies, gents...

As MSN said, we came to an understanding and all is running.

Where MSN calls it "hub and spoke," it (hub and spoke) can also be explained as the "anchor" crypto map (connectivity originates from it). Said differently, imagine the below map as my "first" crypto map:

crypto mapanchormap 110 ipsec-isakmp

Every other crypto map created needs to include the above crypto map as the "baseline" crypto map for vpn connectivity to take place (example given):


crypto map anchormap 111 ipsec-isakmp
set peer 22.33.44.55
match address 120 (Previously configured access-list)
etc...


crypto map anchormap 112 ipsec-isakmp
set peer 11.33.55.44
match address 140 (Previously configured access-list)
etc...



By approaching it from this standpoint, MSN helped bridge the gap

*Heh* it makes since now...

Jay
Forums » Equipment Support » Hardware By Brand » CiscoCisco VPN Dialer woes with consumer WAPS »
« Beware the hardware upgrade...  


Saturday, 28-Nov 11:21:26 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [72] TiVo Sees Record Customer Losses
· [69] In-Flight Internet Headed For Bumpy Landing?
· [69] Verizon CEO: Hulu Will Be Dead Soon
· [62] Thanksgiving Open Thread
· [56] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Why would I want an e reader? [General Questions]
· Why does it take so long? Mail question [General Questions]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Hosts file attributes set to system and hidden [Security]
· Motion Sickness Solutions? [General Questions]
· Windows 7 - Dell ALPS Touchpad driver [Microsoft Help]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· [Vista] Why is HD So Full? [Microsoft Help]