871: ip source-route crypto isakmp policy 1 encr 3des authentication pre-share group 2 crypto isakmp key xxxxx address a.b.c.d crypto isakmp key xxxxx address x.y.z.p crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto ipsec transform-set ESP-3DES-SHA1 esp-3des esp-sha-hmac ! crypto ipsec profile SDM_Profile1 set transform-set ESP-3DES-SHA set isakmp-profile sdm-ike-profile-1 crypto map SDM_CMAP_1 1 ipsec-isakmp description Tunnel toa.b.c.d set peer a.b.c.d set transform-set ESP-3DES-SHA set pfs group2 match address 103 crypto map SDM_CMAP_1 2 ipsec-isakmp description Tunnel tox.y.z.p set peer x.y.z.p set transform-set ESP-3DES-SHA1 match address 104 interface FastEthernet4 ip address dhcp ip nat outside ip virtual-reassembly speed 100 full-duplex crypto map SDM_CMAP_1 interface Vlan1 ip address 10.0.6.3 255.255.255.0 ip pim sparse-mode ip nat inside ip virtual-reassembly ip nat source static 10.0.6.0 interface FastEthernet4 ip nat inside source route-map SDM_RMAP_1 interface FastEthernet4 overload access-list 23 permit 10.0.6.0 0.0.0.255 log access-list 100 remark SDM_ACL Category=4 access-list 100 permit ip 10.0.6.0 0.0.0.255 any access-list 101 remark SDM_ACL Category=18 access-list 101 remark IPSec Rule access-list 101 deny ip 10.0.6.0 0.0.0.255 192.168.110.0 0.0.0.255 access-list 101 remark IPSec Rule access-list 101 deny ip 10.0.6.0 0.0.0.255 10.0.10.0 0.0.0.255 access-list 101 permit ip 10.0.6.0 0.0.0.255 any access-list 102 remark SDM_ACL Category=4 access-list 102 remark IPSec Rule access-list 102 permit ip 10.0.6.0 0.0.0.255 10.0.10.0 0.0.0.255 access-list 103 remark SDM_ACL Category=4 access-list 103 remark IPSec Rule access-list 103 permit ip 10.0.6.0 0.0.0.255 10.0.10.0 0.0.0.255 access-list 104 remark SDM_ACL Category=4 access-list 104 remark IPSec Rule access-list 104 permit ip 10.0.6.0 0.0.0.255 192.168.110.0 0.0.0.255 dialer-list 1 protocol ip permit route-map SDM_RMAP_1 permit 1 match ip address 101