cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
515
Views
0
Helpful
2
Replies

Modifying ACL for interesting traffic, does it require me to clear ipsec sa

tiki_turtle
Level 1
Level 1

I already have a VPN tunnel setup - I would like to add another subnet to the interesting traffic. Once I add the IP / subnet to the ACL for interesting traffic - do I have restart any negotiations between VPN peers?

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

Each individual entry in your crypto map acl for interesting traffic creates a separate ipsec sa (2 actuallu as ipsec sa's are unidirectional).

So no you should not have to clear the existing ipsec sa.

Jon

Thanks Jon - I remember reading that they were unidirectional...but was not aware that each entry creates a seperate sa...

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: