<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ipsec - object group in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981829#M440795</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you need to add one more IP to the object group for the crypto ACL, you would need to add the same on the remote VPN peer as crypto ACL needs to mirror image between the 2 sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once changes has been done, you would need to clear the tunnel as the SA for the new IP will only be built during the negotiation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jun 2012 13:25:57 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-06-15T13:25:57Z</dc:date>
    <item>
      <title>ipsec - object group</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981828#M440794</link>
      <description>&lt;P&gt;Hello and thank you in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a ipsec tunnel setup with the use of object groups. This ipsec tunnel is active and in production.&amp;nbsp; If I need to add one more IP to that object group will I need to do anything for it to take effect or that will be done automatically?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for a stupid question.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981828#M440794</guid>
      <dc:creator>vburshteyn</dc:creator>
      <dc:date>2019-03-11T23:19:50Z</dc:date>
    </item>
    <item>
      <title>ipsec - object group</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981829#M440795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you need to add one more IP to the object group for the crypto ACL, you would need to add the same on the remote VPN peer as crypto ACL needs to mirror image between the 2 sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once changes has been done, you would need to clear the tunnel as the SA for the new IP will only be built during the negotiation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2012 13:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981829#M440795</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-15T13:25:57Z</dc:date>
    </item>
    <item>
      <title>ipsec - object group</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981830#M440796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for responce.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to double check (sorry I am a server tech not cisco)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add the IP to that object-group on both ends&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then &lt;/P&gt;&lt;P&gt;clear ipsec sa peer x.x.x.x &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and that should be it?&amp;nbsp; No need to touch NAT?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2012 13:40:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981830#M440796</guid>
      <dc:creator>vburshteyn</dc:creator>
      <dc:date>2012-06-15T13:40:49Z</dc:date>
    </item>
    <item>
      <title>ipsec - object group</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981831#M440797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh, you got me, yes, you would also need to add that IP to the NONAT (NAT exemption) ACL if you have one configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, it should be:&lt;/P&gt;&lt;P&gt;1) Add IP to both ends of crypto ACL&lt;/P&gt;&lt;P&gt;2) Add IP to NAT exemption on both end&lt;/P&gt;&lt;P&gt;3) Clear tunnel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2012 13:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-object-group/m-p/1981831#M440797</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-06-15T13:44:27Z</dc:date>
    </item>
  </channel>
</rss>

