cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
253
Views
1
Helpful
2
Replies

Crypto map missmatch. Will the tunnel still work?

Chess Norris
Level 4
Level 4

Hello,

I need to add a new network to a crypto map. However, it will take some time for the partner to add the same network on the other side. I want to prepare as much of the configuration at my side as possible. Would it be ok if I add the new network on my side first and then wait for the partner to add it on their side without risking messing up the VPN tunnel. I want to make sure the VPN tunnel continue working for the other networks in the crypto map.

Thanks

/Chess

1 Accepted Solution

Accepted Solutions

@Chess Norris you can add the new ACE (that represent the interesting traffic) to the existing crypto ACL, it should not break the existing SA's on the tunnel. If interesting traffic is generated from your side, those SAs will fail to establish until the peer has configured their side. 

View solution in original post

2 Replies 2

@Chess Norris you can add the new ACE (that represent the interesting traffic) to the existing crypto ACL, it should not break the existing SA's on the tunnel. If interesting traffic is generated from your side, those SAs will fail to establish until the peer has configured their side. 

Thank you for the super fast reply. That's exactly what I wanted to hear.