<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: c2921 interface apply crypto map in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137983#M1113902</link>
    <description>&lt;P&gt;If I have time I will share lab maybe tomorrow&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Sat, 29 Jun 2024 19:07:02 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-06-29T19:07:02Z</dc:date>
    <item>
      <title>c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136101#M1113787</link>
      <description>&lt;P&gt;Hello, please refer my image, and my questions are these:&lt;BR /&gt;1.&lt;BR /&gt;The solution for crypto map, is it working 2 nodes only?&lt;BR /&gt;In my environment, packets from R1 to R2 are crypto, but I need R1 to R3 crypto also. So I want to understand this setting crypto map is working 2 nodes only? Or what can I adjust config?&lt;BR /&gt;2.&lt;BR /&gt;In crypto map solution, packets from R1 to R2 that needs crypto, from R1 to R4 that not needs crypto.&lt;BR /&gt;Can it do it? Or crypto map is not correct solution in this environment?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChinChang_0-1719372554956.png" style="width: 941px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221630iCB95A3480FCB84F1/image-dimensions/941x774?v=v2" width="941" height="774" role="button" title="ChinChang_0-1719372554956.png" alt="ChinChang_0-1719372554956.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 03:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136101#M1113787</guid>
      <dc:creator>Chin Chang</dc:creator>
      <dc:date>2024-06-26T03:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136129#M1113789</link>
      <description>&lt;P&gt;You need to configure Hub and Spoke model&lt;/P&gt;
&lt;P&gt;check below example configuration :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.techtutsonline.com/multiple-site-to-site-vpn-tunnels-on-one-cisco-router/#Configuration_of_VPN_Between_R1_and_R2" target="_blank"&gt;https://www.techtutsonline.com/multiple-site-to-site-vpn-tunnels-on-one-cisco-router/#Configuration_of_VPN_Between_R1_and_R2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you looking spoke to spoke&amp;nbsp; - then you need to look DMVPN or GetVPN solution (you can google it you get&amp;nbsp; N number of examples)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 05:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136129#M1113789</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-06-26T05:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136181#M1113793</link>
      <description>&lt;P&gt;Hi BB,&lt;BR /&gt;Thank your info, but I'm learning your external link, still failed.&lt;BR /&gt;And my 「show crypto isakmp sa」seems working.&lt;BR /&gt;Maybe I will try DMVPN solution.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 06:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136181#M1113793</guid>
      <dc:creator>Chin Chang</dc:creator>
      <dc:date>2024-06-26T06:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136183#M1113794</link>
      <description>&lt;LI-CODE lang="markup"&gt;but I'm learning your external link, still failed.&lt;/LI-CODE&gt;
&lt;P&gt;Not sure i get this - can you give more clarity ?&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Maybe I will try DMVPN solution.&lt;/LI-CODE&gt;
&lt;P&gt;sure that will be way move forward hub and spoke and spoke to spoke.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 06:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136183#M1113794</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-06-26T06:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136198#M1113797</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/243443"&gt;@Chin Chang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check here:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/14133-ios-hub-spoke.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/14133-ios-hub-spoke.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 07:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136198#M1113797</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2024-06-26T07:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136217#M1113800</link>
      <description>&lt;P&gt;Notes&lt;/P&gt;
&lt;P&gt;1-You use hub not SW connect four routers&lt;/P&gt;
&lt;P&gt;2- you test by ping router itself and this not way to tesr ipsec&lt;/P&gt;
&lt;P&gt;3- there is no config of acl use in ipsec?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 08:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136217#M1113800</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-26T08:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136815#M1113830</link>
      <description>&lt;P&gt;Hi M02@rt37,&lt;BR /&gt;Thank your support, but I still failed. I have refer Cisco doc, and same config.&lt;BR /&gt;In my test, the router dr_whoovie have crypto session with sam-I-am, but not crypto session with thidwick.&lt;BR /&gt;And then, sam-I-am interface shutdown / no shutdown, dr_whoovie have session with thidwick, not crypto session with sam-I-am.&lt;BR /&gt;So in my test environment, the crypto session seems working on first 2 nodes, not work in third node. And point to point only, not multipoint.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:31:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5136815#M1113830</guid>
      <dc:creator>Chin Chang</dc:creator>
      <dc:date>2024-06-27T08:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137379#M1113870</link>
      <description>&lt;P&gt;Hi MHM,&lt;BR /&gt;1-You use hub not SW connect four routers&lt;BR /&gt;&amp;gt;&amp;gt;thank your remind, I have replace it by c2960 switch, and other config, environment are same. still failed.&lt;/P&gt;
&lt;P&gt;2- you test by ping router itself and this not way to tesr ipsec&lt;BR /&gt;&amp;gt;&amp;gt;my ping is from R1 interface to R2 interface, should I add PC nodes behind the router? and ping from PC1 to PC2? maybe I will try it.&lt;/P&gt;
&lt;P&gt;3- there is no config of acl use in ipsec?&lt;BR /&gt;&amp;gt;&amp;gt;my ipsec has ACL config, but it is permit ip any any.&lt;BR /&gt;the reason is require ACL command, can not empty.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 09:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137379#M1113870</guid>
      <dc:creator>Chin Chang</dc:creator>
      <dc:date>2024-06-28T09:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137384#M1113871</link>
      <description>&lt;P&gt;do below&amp;nbsp;&lt;BR /&gt;note:-&lt;BR /&gt;1-LO is meaning Loopback&amp;nbsp;&lt;BR /&gt;2- ping from LO to LO (use source in ping) to test IPsec&lt;BR /&gt;3- Spoke have default route toward R4&amp;nbsp;&lt;BR /&gt;4- Hub have static route for each LO connect to Spoke&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;MHM&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hub and spoke.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221871i5082DFD835BEF40A/image-size/large?v=v2&amp;amp;px=999" role="button" title="hub and spoke.png" alt="hub and spoke.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 10:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137384#M1113871</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-28T10:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137980#M1113900</link>
      <description>&lt;P&gt;Thank your help, still failed.&lt;BR /&gt;Currently, we will plan DMVPN, give up crypto map.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2024 18:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137980#M1113900</guid>
      <dc:creator>Chin Chang</dc:creator>
      <dc:date>2024-06-29T18:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137981#M1113901</link>
      <description>&lt;P&gt;To be honest I prefer using dmvpn for hub and spoke' even if I am sure the crypto map I share it work.&lt;/P&gt;
&lt;P&gt;But using legacy crypto map in present of dmvpn is bad idea&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2024 18:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137981#M1113901</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-29T18:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137983#M1113902</link>
      <description>&lt;P&gt;If I have time I will share lab maybe tomorrow&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2024 19:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137983#M1113902</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-29T19:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137999#M1113903</link>
      <description>&lt;P&gt;Hi MHM,&lt;BR /&gt;thank you so much for support.&lt;BR /&gt;i'm familiar DMVPN, if i met trouble, i will post in community, tks!&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2024 20:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5137999#M1113903</guid>
      <dc:creator>Chin Chang</dc:creator>
      <dc:date>2024-06-29T20:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: c2921 interface apply crypto map</title>
      <link>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5138003#M1113904</link>
      <description>&lt;P&gt;You are so welcome&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2024 20:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2921-interface-apply-crypto-map/m-p/5138003#M1113904</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-29T20:49:55Z</dc:date>
    </item>
  </channel>
</rss>

