Actually you can (at least on an ASA 5520 and 5550). Use the command:tunnel-group <peer ip> general-attributes Use the command "annotation"ASA(config-tunnel-general)# annotation < 512 char annotation text string> Show run won't display the annotati...