05-03-2012 02:01 AM
Hi All,
Could somebody tell me if this would work please
crypto isakmp policy 1
authentication pre-share
group 2
crypto isakmp key ABC123 address X.X.X.X 255.255.255.224
!
!
crypto ipsec transform-set TIER-3-SET esp-aes 256 esp-sha-hmac
!
crypto map TIER-3-MAP 10 ipsec-isakmp
set peer X.X.X.X
set transform-set TIER-3-SET
match address 101
interface FastEthernet0
description *** LINK TO INTERNET ***
switchport access vlan 10
no ip address
interface Vlan10
ip address Y.Y.Y.Y 255.255.255.224 - This is an external address
crypto map TIER-3-MAP
Thanks
Nathan
Solved! Go to Solution.
05-03-2012 06:09 AM
Nathan,
Configwise it looks fine, we're missing the ACL, but I guess that part is taken care of ;-)
What's not working? ;-)
M.
05-03-2012 06:09 AM
Nathan,
Configwise it looks fine, we're missing the ACL, but I guess that part is taken care of ;-)
What's not working? ;-)
M.
05-03-2012 06:16 AM
Hi Marcin,
Thanks for the reply, sorry yes i do have the ACl i just forgot to paste that in.
I havent actually applied teh config yet, i just wanted to make sure that it would work with the crypto map on the vlan 10.
Thanks
Nathan
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: