<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Add additional host to IPSEC connection on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3902179#M5750</link>
    <description>&lt;P&gt;So if I have a IPSEC connection allowing let's say local source addresses 10.10.10.10 and 11.11.11.11 to remote end of tunnel 100.1.1.1, and want to add 12.12.12.12 as an addition source host on my local end, do I just make the update under "Local Network" if making the changes in the ASDM? Will that automatically update the crypto map/ACLs?&lt;/P&gt;&lt;P&gt;If I were to update this via CLI, I would just add the new subnet/host to the interesting traffic ACL correct?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:22:00 GMT</pubDate>
    <dc:creator>CiscoBrownBelt</dc:creator>
    <dc:date>2020-02-21T17:22:00Z</dc:date>
    <item>
      <title>Add additional host to IPSEC connection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3902179#M5750</link>
      <description>&lt;P&gt;So if I have a IPSEC connection allowing let's say local source addresses 10.10.10.10 and 11.11.11.11 to remote end of tunnel 100.1.1.1, and want to add 12.12.12.12 as an addition source host on my local end, do I just make the update under "Local Network" if making the changes in the ASDM? Will that automatically update the crypto map/ACLs?&lt;/P&gt;&lt;P&gt;If I were to update this via CLI, I would just add the new subnet/host to the interesting traffic ACL correct?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:22:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3902179#M5750</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2020-02-21T17:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Add additional host to IPSEC connection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3902192#M5752</link>
      <description>You would include this like you say within your interesting traffic ACL. You should ensure the remote end has the new host included also as part if their encryption domain back to you.</description>
      <pubDate>Fri, 02 Aug 2019 16:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3902192#M5752</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-08-02T16:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Add additional host to IPSEC connection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3902238#M5755</link>
      <description>Yes, once you updates from asdm it will update the crypto acl but the&lt;BR /&gt;tunnel has to be restarted for the new entry to be included in IPsec sa&lt;BR /&gt;</description>
      <pubDate>Fri, 02 Aug 2019 17:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3902238#M5755</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-08-02T17:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Add additional host to IPSEC connection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3904130#M5756</link>
      <description>Ok great! Restarted meaning generate interesting traffic?&lt;BR /&gt;Also, currently have manual NAT statements translating the current 2 local source addresses to static original. I would need to add the new host IP to this statement as well correct? Since it is just translating to self/original, is this to make sure the 2 source addresses are not NATTED?</description>
      <pubDate>Tue, 06 Aug 2019 21:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-additional-host-to-ipsec-connection-on-asa/m-p/3904130#M5756</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2019-08-06T21:40:44Z</dc:date>
    </item>
  </channel>
</rss>

