05-11-2005 12:26 AM - edited 02-21-2020 01:46 PM
Hy,
I would like my Cisco router to setup its IPSec tunnel with its peer permanently, instead of waiting for matching traffic to triger the IKE negociation.
How shall I do?
Thanks in advance, have a nice day,
Js
05-17-2005 06:54 AM
There is no direct way for this. However, there is an access list that defines the interesting traffic. You could allow all the traffic in this list. That would make all the traffic encrypted...
05-17-2005 11:17 PM
Agreed! And this is precisely my problem...I don't what all the traffic to be encrypted. Anyway, thanks for your post.
R,
Js
05-18-2005 11:45 AM
If you want a static IPSec tunnel for only 'specific' traffic, then you will need to build your access-list for only that traffic; IPSec tunnels "come up" only when there is traffic to send across it, but once configured, it's automatic.
If your router is running NAT, you need to make sure to EXCLUDE this traffic from the NAT access-list or it will never reach the VPN access-list...
Marc
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide