cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1531
Views
0
Helpful
3
Replies

How to setup a PERMANENT IPSec VPN tunnel?

JMeurisse
Level 1
Level 1

Hy,

I would like my Cisco router to setup its IPSec tunnel with its peer permanently, instead of waiting for matching traffic to triger the IKE negociation.

How shall I do?

Thanks in advance, have a nice day,

Js

3 Replies 3

wong34539
Level 6
Level 6

There is no direct way for this. However, there is an access list that defines the interesting traffic. You could allow all the traffic in this list. That would make all the traffic encrypted...

Agreed! And this is precisely my problem...I don't what all the traffic to be encrypted. Anyway, thanks for your post.

R,

Js

If you want a static IPSec tunnel for only 'specific' traffic, then you will need to build your access-list for only that traffic; IPSec tunnels "come up" only when there is traffic to send across it, but once configured, it's automatic.

If your router is running NAT, you need to make sure to EXCLUDE this traffic from the NAT access-list or it will never reach the VPN access-list...

Marc