Paul,

You can have the same isakmp policy and the same crypto ipsec transform-set
for all of your ipsec vpn's but will need to define a new crypto map and
access-list. Remember to run isakmp disable outside BEFORE making
configuration changes to your interface or you could lock up the PIX.

David Armstrong

""Paul""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> Hi ..
>
> I have setup site to site from a 506 to a 515  .... this all works fine
...
> I now want to set up another site site from a 501 to the same 515 ...
>
> When doing so ... can I use the same ISAKMP policy that I already created
on
> the 515 PIX ???
> If so ... do I just add another 'ISAKMP key **** address' line ???
>
> I guess that I would have to create another 'crypto ipsec transform-set'
!!
>
> Has anyone done anything similiar to this ????
>
> Regards
>
> Paul ...




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=53093&t=53082
--------------------------------------------------
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to