Hi,

On Thu, Mar 11, 2010 at 06:53:46PM +0100, Peter Rathlev wrote:
> Yes, and though I would like to use VTI the other end are not able to.
> So that's a no go.

This surprises me somewhat.  The config variant you use to configure the 
IPSEC stuff on your end should be completely transparent to the other
side, as long as the resulting packets match:

 - IKE phase 1 + 2 proposals
 - IKE phase 2 SA  (= with crypto maps: tied to ACL lines)
 - protocol stacking (IP-in-GRE-in-IPSEC?)

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: pgpEnUTlW7iNK.pgp
Description: PGP signature

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to