11-10-2022 12:55 PM
Thank you! Regards, AP
11-10-2022 12:59 PM
@andreycgipokorskiy assuming you have configured a policy based VPN (with a crypto map), then the crypto ACL needs modifying to specify the new networks to be encrypted.
If you are running a routed based VPN with a VTI, this does not use a crypto ACL to specify what should be encrypted. You just need to ensure the route is advertised using the dynamic routing protocol. If not using a routing protcol, the remote peer would need to define a static route over the tunnel.
11-10-2022 01:08 PM
Hello Rob
If I got it right the selector mean that the selectors are the IP or range that been added to ACL and that ACL was added to crypto-map. Is it correct? And if we didn't see the local and remote selector in the tunnel it is mean that other side (client) have no or removed our IP from his ACL?
Thank you!
11-10-2022 01:15 PM
Hi @andreycgipokorskiy yes, the traffic selector refers to the interesting traffic defined in the ACL that should be encrypted.
Interesting traffic would need to be sent to/from the local/remote traffic selector in order for the IPSec SA to be established. So if you do not see the IPSec SA for the traffic selector, either there is a problem on the local or remote end or simply you just need to generate some traffic.
11-10-2022 01:18 PM
Thanks for your help Rob!
11-13-2022 10:34 AM
you dont see selector are the new LAN you add can ping other side ??
11-14-2022 06:18 AM
Hello MHM
No I can't as this IP on client side and ICMP is not allowed
11-14-2022 06:21 AM
not ICMP any traffic can pass between new local LAN and remote LAN ?
11-28-2022 07:56 AM
Hello MHM
I can't ping remote LAN IP
I tried to find if the remote site lost our external IP in ACL
No lack
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide