03-15-2015 05:14 AM
Hi
I wish to create another crypto map policy going to the same peer address but have a different access-list
access-list eddie-1 extended permit ip 100.1.1.1. 255.255.255.224 host 127.127.1.1
access-list eddie-2 extended permit ip 200.1.1.1 255.255.255.224 host 227.227.1.1
crypto map VPN_eddie-1 1 match address eddie-1
crypto map VPN eddie-1 set pfs group5
crypto map VPN eddie-1 set peer 8.19.1.22
crypto map VPN eddie-1 set ikev1 transform-set ESP-AES-256-SHA
crypto map VPN eddie-1 set security-association lifetime seconds 86400
crypto map VPN_eddie-2 1 match address eddie-2
crypto map VPN eddie-2 set pfs group5
crypto map VPN eddie-2 set peer 8.19.1.22
crypto map VPN eddie-2 set ikev1 transform-set ESP-AES-256-SHA
crypto map VPN eddie-2 set security-association lifetime seconds 86400
Is it possible ?
03-15-2015 07:29 AM
Why do you need to do that ?
Your settings are the same for each entry so just combine the acl and have one entry.
Jon
03-16-2015 03:16 AM
Would this achieve the same purpose ?
access-list eddie-1 extended permit ip 100.1.1.1. 255.255.255.224 host 127.127.1.1
access-list eddie-2 extended permit ip 200.1.1.1 255.255.255.224 host 227.227.1.1
crypto map VPN_eddie-1 match address eddie-1
crypto map VPN_eddie-2 match address eddie-2
crypto map VPN eddie-1 set pfs group5
crypto map VPN eddie-1 set peer 8.19.1.22
crypto map VPN eddie-1 set ikev1 transform-set ESP-AES-256-SHA
crypto map VPN eddie-1 set security-association lifetime seconds 86400
03-16-2015 06:18 AM
Why do you think you need separate acls for your crypto map.
Jon
03-16-2015 06:41 AM
Only this ACL "eddie-2" will be included in the crypto engine and other ACL has nothing do with the tunnel.
03-15-2015 08:35 AM
Yes it is possible.
There isn't any benefit doing that but instead you can use just one ACL map to single crypto instance for tunnel bound traffic to same tunnel peer.
I cannot think of a reason why you want to do this.
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide