cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
513
Views
0
Helpful
4
Replies

Cisco router -multiple tunnels can i setup multiple isakmp identities?

Brett Martin
Level 1
Level 1

Hello, I have a cisco 2811 and have setup 2 ipsec tunnels. My router is behind a firewall with 1-1 NAT. I can get one tunnel working as long as IKE peer id is the interface IP address. The second tunnel will only work if i set the crypto isakmp identity to hostname, and it works. I can only have one work at a time. The tunnel is souced on the same physical interface.

1 Accepted Solution

Accepted Solutions

Both ipv4 and ipv6. If ipv6 is required as identity, you would have to use "address ipv6".

You would have to use the "set isakmp-profile <profilename>" under the crypto map to link them to the tunnel. An example for this is given here:

https://supportforums.cisco.com/document/11935411/site-site-between-cisco-ios-router-using-isakmp-profile-and-certificate

View solution in original post

4 Replies 4

Rahul Govindan
VIP Alumni
VIP Alumni

I believe this is possible. You would have to use the "self-identity" command under an isakmp profile (one for each peer) and tie that profile into a crypto map entry. You would have to have the right condition to match the peer to the correct isakmp profile. Command info is here:

http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/s1/sec-s1-cr-book/sec-cr-s1.html#wp2948613298

Hi Rahul,

Thank you for your response! Is this command only available for ipv6 and not ipv4? Is the ipv6 command just to allow you to specify ipv6 if desired?.

Additionally, howdo I link this to my tunnel?

Both ipv4 and ipv6. If ipv6 is required as identity, you would have to use "address ipv6".

You would have to use the "set isakmp-profile <profilename>" under the crypto map to link them to the tunnel. An example for this is given here:

https://supportforums.cisco.com/document/11935411/site-site-between-cisco-ios-router-using-isakmp-profile-and-certificate

Thank you very much Rahul--that worked!!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: