I added two remote dynamic DSL routed connections (no fixed addresses available) to a VPN network which was previously all static IPs. I made changes on the 2600 hub router to accomodate the dynamic address from the new 1700 series spoke DSL routers. I have VPN connections going to the dynamic IP DSL networks, and I wanted to be able to identify the spoke IP DSL addresses in case they changed. I also anticipate that there may be a third dynamic DSL line soon.
When I run "sho crypto ipsec sa" on the spoke routers, I see the connection data. On the 2600, I see the output below with the 10.11.x.x net listed, but not the 10.10.x.x. I would like to see all the dynamic IP addresses listed like the static addresses. I'm assuming the issue is with the "crypto map cm-cryptomap 10 ipsec-isakmp dynamic dynmap" line. If I enter a second 'crypto map' line with "11" replacing "10" it doesn't appear, just the first line. My edited config from the hub router is below. What's the best practice here? Thanks.
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...