10-07-2025 04:35 AM
Hello,
I need to add a new network to a crypto map. However, it will take some time for the partner to add the same network on the other side. I want to prepare as much of the configuration at my side as possible. Would it be ok if I add the new network on my side first and then wait for the partner to add it on their side without risking messing up the VPN tunnel. I want to make sure the VPN tunnel continue working for the other networks in the crypto map.
Thanks
/Chess
Solved! Go to Solution.
10-07-2025 04:40 AM
@Chess Norris you can add the new ACE (that represent the interesting traffic) to the existing crypto ACL, it should not break the existing SA's on the tunnel. If interesting traffic is generated from your side, those SAs will fail to establish until the peer has configured their side.
10-07-2025 04:40 AM
@Chess Norris you can add the new ACE (that represent the interesting traffic) to the existing crypto ACL, it should not break the existing SA's on the tunnel. If interesting traffic is generated from your side, those SAs will fail to establish until the peer has configured their side.
10-07-2025 04:43 AM
Thank you for the super fast reply. That's exactly what I wanted to hear.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide