Sorry if I didn't see this but I think you should apply that access-list 111 to int gi0/0. The pool is fine considering you're using the overload statement at the end but having 1 ip there would not make a difference. I think applying the ACL should do the trick for you.
int gi0/0
access-group...
You can also set up GRE tunnels over the IPSEC tunnels and that will allow you to pass routing protocol information over the ipsec tunnel. Example provided is using OSPF.
http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800a43f6.shtml
But the floating...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.