04-15-2009 08:57 AM - edited 02-21-2020 04:12 PM
I already have a VPN tunnel setup - I would like to add another subnet to the interesting traffic. Once I add the IP / subnet to the ACL for interesting traffic - do I have restart any negotiations between VPN peers?
04-15-2009 09:44 AM
Each individual entry in your crypto map acl for interesting traffic creates a separate ipsec sa (2 actuallu as ipsec sa's are unidirectional).
So no you should not have to clear the existing ipsec sa.
Jon
04-15-2009 09:46 AM
Thanks Jon - I remember reading that they were unidirectional...but was not aware that each entry creates a seperate sa...
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: