Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

How do I put crypto dynamic-map and crypto map under one map?

I have a PIX connected to two sites using VPN. the other two sites are running SonicWall and Checkpoint respectively. The SonicWall side is using a dynamic DHCP ip address, while the checkpoint side is using a static ip address. It looks like PIX does not allow me to put 2 crypto map on my external PIX interface, but how do I achieve it when I have a dynamic peer and a static peer at the remote sites?

my configuration is as shown:

PIX Version 6.0(4)

sysopt connection permit-ipsec

no sysopt route dnat

crypto ipsec transform-set test esp-3des esp-sha-hmac

crypto ipsec transform-set panda esp-des esp-sha-hmac

crypto dynamic-map pixosw 10 match address 120

crypto dynamic-map pixosw 10 set transform-set test

crypto map pixtockpt 40 ipsec-isakmp

crypto map pixtockpt 40 match address 140

crypto map pixtockpt 40 set peer 200.1.1.1

crypto map pixtockpt 40 set transform-set panda

crypto map pixtockpt interface outside ( i can't add in the pixosw map here)

isakmp enable outside

isakmp key ******** address 200.1.1.1 netmask 255.255.255.224

isakmp policy 20 authentication pre-share

isakmp policy 20 encryption 3des

isakmp policy 20 hash sha

isakmp policy 20 group 2

isakmp policy 20 lifetime 28800

isakmp policy 40 authentication pre-share

isakmp policy 40 encryption des

isakmp policy 40 hash sha

isakmp policy 40 group 2

isakmp policy 40 lifetime 28800

3 REPLIES
Silver

Re: How do I put crypto dynamic-map and crypto map under one map

I believe you only need the following:

crypto map pixtockpt 50 ipsec-isakmp dynamic pixosw

Thanks.

Cisco Employee

Re: How do I put crypto dynamic-map and crypto map under one map

Hi,

You can apply only one crypto map to an interface. You can follow the below URL and get things up and running within no time :-)

http://www.cisco.com/warp/public/110/pixpixvpn.html

Regards,

Arul

New Member

Re: How do I put crypto dynamic-map and crypto map under one map

Thank you very much!! I am going to try this out!

126
Views
0
Helpful
3
Replies