Hi,

On Fri, Dec 17, 2010 at 03:33:30PM +0300, Righa Shake wrote:
> crypto map MYCRYPTOMAP 10 ipsec-isakmp
>  set peer X.X.X.X
>  set transform-set MYCRYPTO1
>  match address VPNTRAFF
> crypto map MYCRYPTOMAP 20 ipsec-isakmp
>  set peer Y.Y.Y.Y
>  set transform-set MYCRYPTO2
>  match address VPNTRAFF
> crypto map MYCRYPTOMAP 30 ipsec-isakmp
>  set peer Z.Z.Z.Z
>  set transform-set MYCRYPTO2
>  match address VPNTRAFF

Since the "match address" block is the same, there's no reason why the
router should establish SAs to Y and Z.

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: pgpC4XGeKLDye.pgp
Description: PGP signature

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to