IP Route

Unanswered Question
Jul 10th, 2007

Hi Guys,


I need some little help. Im trying to establish a Site2Site VPN going to MCI Verizon. Problem is my WAN Interface that im going to peer is a subinterface of the FE0/1. And the Primary is giving as SRC on the IPSEC info. It should be the Subinterface of the FE0/1.


ex.


interface FastEthernet0/1

ip address 192.42.75.246 255.255.255.252 secondary

ip address 10.116.254.254 255.255.255.252


Router#sh crypto isakmp sa

dst src state conn-id slot status

115.211.121.238 10.116.254.254 MM_NO_STATE 0 0 ACTIVE


My question is, how can i change the IP of the Cisco is giving to send the subinterface IP and the the Primary IP as SRC address?


Or should i swap the designation of the IPs in the interface instead such as Im going to put 192.42.75.246 as Primary and the other as Secondary?


Thanks, let me know if im expressing it correctly.


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
royalblues Tue, 07/10/2007 - 11:07

Friend,


If you want the IPs to be sourced from the subinterface then the crypto map should be applied to the subinterface.


The config you posted do not show the subinterface configuration but only a secondary address on the interface.


am i missing something here?


Narayan

Actions

This Discussion