Hello Decio.Yes. As long as one end has a statically assigned IP on one side, the remote side with the dynamically assigned address should be able to initiate the VPN. The obvious restriction is that the VPN cannot be initated from the static side.Th...
Hi Mike,When you add tunnel "protection ipsec profile", this will indeed create the entry in the security policy database to encrypt the tunnel itself. The generated crypto map will actually match either GRE between the endpoints (when in the default...
Hi Damo, Assuming that you don't need IKE to listen to the entire world, but only to specific peers, you can potentially use the control-plane option for access, e.g. as follows:access-list test extended permit udp host 10.48.67.145 interface outsid...
Hello Mike, I am not sure I understand the question. If the question is about having 3 different inside vrf (ivrf) carried to another site through one single VTI tunnel, with its endpoints either in the global routing table or in a different fvrf (fr...