I was wondering if anyone knew if it was possible to apply the same crypto map (or an identical crypto map at least) to two interfaces on the same ASA?
I have two ethernet circuits being handed off by two ISPs at the Core of a hub and spoke IPVPN network, with different circuit addressing, and would like to use one of these circuits as a backup endpoint for the VPN tunnels.
I know it is fairly easy to specify a backup peer in the PIX firewalls at the remote locations, but am uncertain as to how the ASA will decide which crypto map to use if it has two maps that matched the traffic it sees. Are the priority levels in a cyrpto map locally significant or global?