Paul, You can have the same isakmp policy and the same crypto ipsec transform-set for all of your ipsec vpn's but will need to define a new crypto map and access-list. Remember to run isakmp disable outside BEFORE making configuration changes to your interface or you could lock up the PIX.
David Armstrong ""Paul"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Hi .. > > I have setup site to site from a 506 to a 515 .... this all works fine ... > I now want to set up another site site from a 501 to the same 515 ... > > When doing so ... can I use the same ISAKMP policy that I already created on > the 515 PIX ??? > If so ... do I just add another 'ISAKMP key **** address' line ??? > > I guess that I would have to create another 'crypto ipsec transform-set' !! > > Has anyone done anything similiar to this ???? > > Regards > > Paul ... Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=53093&t=53082 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]