cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
346
Views
0
Helpful
1
Replies

multiple instances of dynamic vpn

ronshuster
Level 1
Level 1

We currently have a number of remote sites connecting to our head office using dynamic VPN (DefaultL2LGroup),

I would like to know if it is possible to have multiple instances of this, ie. have different groups with different properties (interesting traffic, key, etc.)

As far as I see on the IOS and online, there is only one instance of this available.

1 Reply 1

Ivan Martinon
Level 7
Level 7

The only possible way to have this would be to land each dynamic connection to a separate tunnel-group, and the only way to do this would be to use certificates as the ike negotiation rather than preshared key, with pki you can use a value of the cert to match it to a specific tunnel group or use the fqdn for tunnel group matching.