cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
641
Views
0
Helpful
5
Replies

Multiple IPSEC tunnels on one ISAKMP policy

togrul.azizli
Level 1
Level 1

Is it possible to create multiple IPSEC tunnels (site-to-site or RemoteAccess) with only one ISAKMP policy? 

5 Replies 5

Puneesh Chhabra
Cisco Employee
Cisco Employee

Yes, as long as it matches the peer policies, you do not need multiple ISAKMP policies.

 

Regards,

Puneesh

If you find the answer helpful, please mark it as correct so others can benefit from the discussion.

Hi Puneesh

Is isakmp policy IDs or names have to be same on both sides . 

#crypto isakmp policy 100 

Does policy number 100 has to be same on another device or devices?

This is the isakmp policy sequence number and is only locally significant.

Numbers do not need to match on both ends.

 

Regards,

Puneesh

If you find the answer helpful, please mark it as correct so others can benefit from the discussion.

So if in my ASA I created 5 isakmp policies and 10 remote sites or remote vpn users , so they have to search my ASA in order to find isakmp policy that matches their's. Is this correct?

Yes, they search from top to bottom.

 

Regards,

Puneesh

If you find the answer helpful, please mark it as correct so others can benefit from the discussion.