cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
314
Views
0
Helpful
1
Replies

vpn pool ip address as a subinterface on the firewall

network770
Level 1
Level 1

we have a number of dynamic vpns and we need to be able to access them from remote acess vpn (ipsec), problem is that given the remote sites are on Dvpn the SA's constantly gets lost if there's no traffic.  So we want to create a script that will send icmp packets every so often to an ip address of the vpn pool... problem is that it's only a pool and there's no interface with this ip address.

Question is : can I exclude one ip address from the vpn pool and make it as a sub-interface on the inside interface of the firewall such that I'll be able to ping it?

1 Reply 1

you can't exlude one ip from the pool. Also, you can create a sub-interface and assign it an IP from a subnet that differs from the existing interfaces.

Review Cisco Networking for a $25 gift card