11-03-2011 08:18 AM - edited 02-21-2020 05:41 PM
Hi All,
I need to put additional host on the existing crypto-interesting ACL on live tunnel with real-time traffic.
I have remote side network engineer to apply the same on their end.
My question is will it interrupt existing tunnel/traffic if we put additional hosts on the ACL simultaneously on both sides?
Thanks!
Solved! Go to Solution.
11-03-2011 08:31 AM
Each permit entry in TS in ACL will generate it's own IPsec SA.
There should be no impact on existing services - just pay extra attention not to introduce any overlap into ACLs.
A separate matter is that very often to update crypto map DB we sometimes need to remove and re-add crypto map configuration - which will cause traffic distruption.
Marcin
11-03-2011 08:31 AM
Each permit entry in TS in ACL will generate it's own IPsec SA.
There should be no impact on existing services - just pay extra attention not to introduce any overlap into ACLs.
A separate matter is that very often to update crypto map DB we sometimes need to remove and re-add crypto map configuration - which will cause traffic distruption.
Marcin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide