10-28-2018 05:51 AM - edited 02-21-2020 09:29 PM
Hello!
Interesting, how mach can I add subnets to the IPsec tunnel on Cisco ASA?
Now, when I add to the tunnel, some subnets are not visible in the tunnel,
but after the rebuild, others not are visible...
Configuration:
Cisco ASA 5515-X (~30 subnets) <= IPsec (ikev1) => Cisco ASA 5520 (~20 subnets)
What do you think about this interesting situation?
10-28-2018 07:26 AM
The IKEv1 SA will establish when any interesting traffic is presented to a tunnel endpoint.
The IPsec SAs (which the subnets are included in) form dynamically when pairwise traffic flows. So some might remain inactive if there's no communications between those particular subnets.
10-28-2018 12:24 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide