01-18-2019 10:43 PM
Hi, I am instructed that add a specific IP to Encryption domain/interesting traffic. But I don't know how ?
How can I add specific IP to that. Thanks...
Solved! Go to Solution.
01-19-2019 05:10 AM
Hi,
If this VPN is already running then you will must find a Crypto-map and one ACL is also applied in the Crypto-map with configuration command "Match address,,,,,,,". (,,, ACL number or name).
See here a example:
ip access-list extended VPN-TRAFFIC <ACL>
10 permit ip <Local LAN Subnet> any
11 permit ip <source IP/Subnet> <Destinatio IP/Subnet> <Add this new entry>
!
!
crypto map IPSEC-SITE-TO-SITE-VPN 10 ipsec-isakmp <Crypto MAP>
match address VPN-TRAFFIC <ACL applied in Crypto-MAP>
set peer <WAN IP of remote end>
set transform-set MY-SET
Note: ACL name/Number or Crypto map may be different in your configuration.
If you are not sure then please share running configuration. You may also denied the Same subnet source and destination subnet in your NAT acl.
Regards,
Deepak Kumar
01-19-2019 03:25 AM
Look at the corresponding "crypto map" configuration there you find a referenced ACL "match address ..." that specifies which traffic should be protected with this VPN. Just add another line with the new traffic needs.
01-19-2019 05:10 AM
Hi,
If this VPN is already running then you will must find a Crypto-map and one ACL is also applied in the Crypto-map with configuration command "Match address,,,,,,,". (,,, ACL number or name).
See here a example:
ip access-list extended VPN-TRAFFIC <ACL>
10 permit ip <Local LAN Subnet> any
11 permit ip <source IP/Subnet> <Destinatio IP/Subnet> <Add this new entry>
!
!
crypto map IPSEC-SITE-TO-SITE-VPN 10 ipsec-isakmp <Crypto MAP>
match address VPN-TRAFFIC <ACL applied in Crypto-MAP>
set peer <WAN IP of remote end>
set transform-set MY-SET
Note: ACL name/Number or Crypto map may be different in your configuration.
If you are not sure then please share running configuration. You may also denied the Same subnet source and destination subnet in your NAT acl.
Regards,
Deepak Kumar
01-23-2019 05:17 AM
Thanks for your detailed informations...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide