<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Applying two crypto map to same interface caused outage in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080182#M1069893</link>
    <description>&lt;P&gt;I was asking if we can apply two different crypto map names to same interface?&lt;/P&gt;&lt;P&gt;for example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;crypto map&amp;nbsp; test1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;crypto map&amp;nbsp; test 2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2020 03:31:26 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2020-05-06T03:31:26Z</dc:date>
    <item>
      <title>Applying two crypto map to same interface caused outage</title>
      <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080119#M1069886</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems on Cisco ASA 8.2 we have remote vpn configured with crypto&amp;nbsp; map name VPN.&lt;/P&gt;&lt;P&gt;I did config for site to site IPSEC tunnel with new crypto map name L2L.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i apply this new crypto map to the outside interface then old crypto map VPN was no longer applied to the&lt;/P&gt;&lt;P&gt;outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to confirm if this is by design?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Old crypto map policy number is 10&lt;/P&gt;&lt;P&gt;new crypto map plicy number was 20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 00:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080119#M1069886</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2020-05-06T00:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Applying two crypto map to same interface caused outage</title>
      <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080169#M1069892</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can do this - but you need to increase&amp;nbsp;sequence number - in my example its 10 and 20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;crypto map WAN_MAP 10 match address 123&lt;BR /&gt;crypto map WAN_MAP 10 set peer 3.13.24.2&lt;BR /&gt;crypto map WAN_MAP 10 set ikev1 transform-set dessha&lt;BR /&gt;crypto map WAN_MAP 10 set security-association lifetime seconds 28800&lt;BR /&gt;crypto map WAN_MAP 10 set security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map WAN_MAP 10 set reverse-route&lt;BR /&gt;crypto map WAN_MAP 20 match address 11&lt;BR /&gt;crypto map WAN_MAP 20 set pfs group14&lt;BR /&gt;crypto map WAN_MAP 20 set peer 9.16.43.8&lt;BR /&gt;crypto map WAN_MAP 20 set ikev2 ipsec-proposal AES256-SHA512&lt;BR /&gt;crypto map WAN_MAP 20 set security-association lifetime seconds 3600&lt;BR /&gt;crypto map WAN_MAP 20 set security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;crypto map WAN_MAP interface &amp;lt;outside interface name&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 02:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080169#M1069892</guid>
      <dc:creator>kapydan88</dc:creator>
      <dc:date>2020-05-06T02:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Applying two crypto map to same interface caused outage</title>
      <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080182#M1069893</link>
      <description>&lt;P&gt;I was asking if we can apply two different crypto map names to same interface?&lt;/P&gt;&lt;P&gt;for example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;crypto map&amp;nbsp; test1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;crypto map&amp;nbsp; test 2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 03:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080182#M1069893</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2020-05-06T03:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Applying two crypto map to same interface caused outage</title>
      <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080183#M1069894</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I was asking if we can apply two different crypto map names to same interface? - No.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 03:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080183#M1069894</guid>
      <dc:creator>kapydan88</dc:creator>
      <dc:date>2020-05-06T03:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Applying two crypto map to same interface caused outage</title>
      <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080201#M1069899</link>
      <description>&lt;P&gt;thanks for answering the question.&lt;/P&gt;&lt;P&gt;Currently we have sequence number 10 and 65535 for remote vpn users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i use sequence number 20&amp;nbsp; for IPSEC lan to lan tunnel then it should not cause any issues right?&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 04:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080201#M1069899</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2020-05-06T04:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Applying two crypto map to same interface caused outage</title>
      <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080318#M1069903</link>
      <description>&lt;P&gt;Only one "crypto map &amp;lt;name&amp;gt;" can be applied to a given interface at one time.&lt;/P&gt;
&lt;P&gt;As implied, we use sequence numbers within the crypto map to accommodate multiple distinct VPNs.&lt;/P&gt;
&lt;P&gt;As long as the ACLs for matching ("interesting") traffic don't have any overlaps or conflicts it will work fine.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 08:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080318#M1069903</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-05-06T08:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Applying two crypto map to same interface caused outage</title>
      <link>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080414#M1069911</link>
      <description>&lt;P&gt;Many Thanks Marvin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 11:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/applying-two-crypto-map-to-same-interface-caused-outage/m-p/4080414#M1069911</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2020-05-06T11:51:59Z</dc:date>
    </item>
  </channel>
</rss>

