I belive it works something like this:The ids has both keys and does decrypt the data. It makes a copy of the encrypted packet, de-cryptps and inspects the copy. Based on what is in the decrypted packet it either forwards, alerts or drops the origi...
Is this possible with VPN 3005 boxes? E.g:A - B -- CWhere A and B are 3005 with ipsec tunnel established and C is a VPN client.Would it be possible for C to access the LAN on A side over the tunnel?