This client needs to create a vpn ( ipsec )tunnel using two asa'a. I had a cisco documentation link being posted by one of the learned posters here.
This link shows the configuration with a tunnel group. I came across another general site, which shows one without a tunnel group using asa's.
Please help which one is better and appreciate if i could understand why.
thsts a deprecated command
however i tried it out in my lab just to see what would happen, it took the commadn but this is what it made by default
ASA-1(config)# crypto isakmp key cisco address x.x.x.x
ASA-1(config)# sh run tunn
ASA-1(config)# sh run tunnel-group
tunnel-group 18.104.22.168 type ipsec-l2l
tunnel-group 22.214.171.124 general-attributes
tunnel-group 126.96.36.199 ipsec-attributes
isakmp keepalive threshold 10 retry 2
so you can clearly see it took the command but it did not like it
while you try to put the command it does say that it is deprecated
So to summarize ----------------------- always use tunnel-group : )