did you create your access-group?first you want to make sure to create your ACL first, then create the access-groupcreating access-group before the ACL will not work. it is part of the cisco mechanics.there is no limitations for the VTI in terms of A...