05-03-2012 02:01 AM
Hi All,
Could somebody tell me if this would work please
crypto isakmp policy 1
authentication pre-share
group 2
crypto isakmp key ABC123 address X.X.X.X 255.255.255.224
!
!
crypto ipsec transform-set TIER-3-SET esp-aes 256 esp-sha-hmac
!
crypto map TIER-3-MAP 10 ipsec-isakmp
set peer X.X.X.X
set transform-set TIER-3-SET
match address 101
interface FastEthernet0
description *** LINK TO INTERNET ***
switchport access vlan 10
no ip address
interface Vlan10
ip address Y.Y.Y.Y 255.255.255.224 - This is an external address
crypto map TIER-3-MAP
Thanks
Nathan
Solved! Go to Solution.
05-03-2012 06:09 AM
Nathan,
Configwise it looks fine, we're missing the ACL, but I guess that part is taken care of ;-)
What's not working? ;-)
M.
05-03-2012 06:09 AM
Nathan,
Configwise it looks fine, we're missing the ACL, but I guess that part is taken care of ;-)
What's not working? ;-)
M.
05-03-2012 06:16 AM
Hi Marcin,
Thanks for the reply, sorry yes i do have the ACl i just forgot to paste that in.
I havent actually applied teh config yet, i just wanted to make sure that it would work with the crypto map on the vlan 10.
Thanks
Nathan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide