Sorry, posted same thing in wrong forum(ccna)
Please advise thanks: ( trying to add a new subnet to a site to site,
(10.xxx.34.0/255.255.255.0)) - the other peer is a cisco asa
show crypto ipssec sa :
protected vrf: (none)
local ident (addr/mask/prot/port): (xxx.119.48.0/255.255.255.128/0/0)
remote ident (addr/mask/prot/port): (10.xxx.34.0/255.255.255.0/0/0)
current_peer xxx.119.51.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0
#pkts not decompressed: 0, #pkts decompress failed: 0
#send errors 0, #recv errors 0
local crypto endpt.: 68.xxx.227.225, remote crypto endpt.: xxx.119.51.2
path mtu 1500, ip mtu 1500, ip mtu idb FastEthernet0/0
current outbound spi: 0x0(0)
inbound esp sas:
inbound ah sas:
inbound pcp sas:
outbound esp sas:
outbound ah sas:
outbound pcp sas:
show crypto map:
show crypto map
Crypto Map "SDM_CMAP_2" 1 ipsec-isakmp
Description: Tunnel toxxx.119.51.2
Peer = xxx.119.51.2
Extended IP access list 102
access-list 102 permit ip xxx.119.48.0 0.0.0.127 xxx.119.41.0 0.0.0.255
access-list 102 permit ip xxx.119.48.0 0.0.0.127 xxx.119.16.0 0.0.0.255
access-list 102 permit ip xxx.119.48.0 0.0.0.127 xxx.119.47.0 0.0.0.255
access-list 102 permit ip xxx.119.48.0 0.0.0.127 10.xxx.34.0 0.0.0.255
Current peer: xxx.119.51.2
Security association lifetime: 4608000 kilobytes/3600 seconds
PFS (Y/N): Y
DH group: group1
Transform sets={
VPN,
}
Interfaces using crypto map SDM_CMAP_2:
FastEthernet0/0