01-27-2022 06:12 PM
hello, I wondering if ACL line number is equal sa number?
Scenario:
NY office has 1 subnet 192.168.0.0/24 and CA office has 2 subnets : 172.16.0.0/12 and 10.0.0.0/8
NY and CA have a ipsec vpn.
I wanna know it will generate 2 ipsec phase 2 sa ?
Solved! Go to Solution.
01-27-2022 11:15 PM
Hi @ronald.su,
No, ACL line number is not necessarily equal to established SAs (assuming that is what you are asking). It is possible that you have 5 different ACL entries, and that only one SA is established (e.g. one that is #3 in your ACL). but, it is also possible to have all 5 SAs established.
BR,
Milos
01-27-2022 11:15 PM
Hi @ronald.su,
No, ACL line number is not necessarily equal to established SAs (assuming that is what you are asking). It is possible that you have 5 different ACL entries, and that only one SA is established (e.g. one that is #3 in your ACL). but, it is also possible to have all 5 SAs established.
BR,
Milos
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide