Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

I need help setting up VPN clients (software)

Status
Not open for further replies.

ianbla

IS-IT--Management
Oct 31, 2001
156
GB
We already have a VPN to a customer site which is on the outside iunterfac. In the documentation to set up a software client it tells you to apply the following command "crypto map mymap interface outside" as soon as I do this the existing customer link is lost and poeple are nasty to me and shout, how can I stop them shouting at me and get both working, I must be missing something.

Many thanks
 
You can only apply one cryptomap to an interface so if you rename the cryptomap it will drop all current tunnels. What you need is a different instance of the tunnel so if you currently have let´s say crypto map anymap 10 ... you will need crypto map anymap 20 ... for the new crypto commands. However, if you configure an incomplete crypto map all traffic will be encrypted and you will loose connection to the Internet, to avoid this issue it is recommended to disable the crypto map from the interface, configure the new tunnel and then enable the crypto map on the interface again. Of course this will disrupt current tunnels so you may want to do it at a time where no tunnles are used.
 
Thanks for the heads up.

I have just been told that I need to establish another VPN tunnel to a different customer. Am I right in saying that I can do this on the PIX515e and have seperate ACLS for the 2 links.
 
you need separate ACLs for interesting traffic you also need a different ACL to bypass NAT and as explained earlier you need a different instance of the crypto map.
 
Do you know if there is any good papers out there explaining all the differnt elements that make up the VPN connection

Transform set
dynamic map
crypto map

I find it a bit confusing.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top