- Bronze, 100 points or more
I have a 7206 router with an ISA VPN card in it. I want to use a static route to point traffic at a particular VPN.
The interface that all of the VPNs terminate on is fa0/0, it has the outside IP that the remote PIX501s negotiate isakmp etc with.
I'm trying to troubleshoot an issue, but would like to clarify one thing before I move on.
If I just point the static route at the interface, will the router pick the correct VPN to put the traffic onto? How does it know? Does it go through all the IPSEC SAs and determine which one to put the traffic into?
Internal network > 7206 (VPN>>) > internet > (<<VPN)pix501 > 10.1.1.0
I want to put in a static saying that if the primary routes to this subnet disappear, use this static (VPN is being used as a backup in this case).
Would the following route work? This route will be redistributed to the rest of my internal network.
ip route 10.1.1.0 255.255.255.0 fa0/0 200