12-11-2007 12:45 AM - edited 02-20-2020 09:39 PM
Hi,
Let's suppose that we have the following crypto map policy on a PIX firewall:
crypto map VPN-CRYPTO-MAP 10 match address L2L-TUNNEL-01
crypto map VPN-CRYPTO-MAP 10 set peer 1.1.1.1
crypto map VPN-CRYPTO-MAP 10 set transform-set ESP-3DES-MD5
crypto map VPN-CRYPTO-MAP 20 match address L2L-TUNNEL-01
crypto map VPN-CRYPTO-MAP 20 set peer 2.2.2.2
crypto map VPN-CRYPTO-MAP 20 set transform-set ESP-3DES-MD5
Please note that the ACL to be matched for both peers is the same. My question is: In case peer 1.1.1.1 fails, is the IPSEC tunnel going to be established with peer 2.2.2.2 instead for the same traffic?
Thanks in advance.
12-11-2007 01:02 AM
Hi
The simple anwser is i'm not sure without testing however could i ask what you are trying to achieve. If it is redundancy you can have multiple "set peer" statements under the same crypto map entry and it will try them in order.
Apologies if you already knew this.
Jon
12-11-2007 01:07 AM
Hi Jon,
Yes correct, I need peer 2.2.2.2 to act as backup only and being used in case 1.1.1.1 stops responding.
So you're saying that configuring the crypto-map as listed below will achieve that?
crypto map VPN-CRYPTO-MAP 10 match address L2L-TUNNEL-01
crypto map VPN-CRYPTO-MAP 10 set peer 1.1.1.1
crypto map VPN-CRYPTO-MAP 10 set peer 2.2.2.2
crypto map VPN-CRYPTO-MAP 10 set transform-set ESP-3DES-MD5
Thanks.
12-11-2007 01:20 AM
Hi
Yes that should do it.
Jon
12-11-2007 01:27 AM
Thanks Jon, I have one more question please. What happens if peer 1.1.1.1 gets back up? Is IKE going to try to renegotiate with it automatically?
12-11-2007 01:31 AM
Ahh well, to be honest i can't say for sure. I assume it will keep using 2.2.2.2 until the tunnel is torn down and it then tries to start it up again but without testing i'm not sure.
If i get the chance i'll knock this up in our lab but it's going to be a busy week so there might be a delay.
Jon
12-11-2007 01:38 AM
Well thanks Jon. If u get the chance to test it plz let me know :-)
Cheers
12-19-2007 02:17 AM
Well it shoul dwork on 6.3. What is the solution for 7.2?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: