crypto dynamic-map Outside_dyn_map 10 set reverse-route
--> if you are running dynamic routing protocols, that command will inject a static route back towards your dynamic routing protocol for the vpn client pool/assigned address. Also need configure: redistribute static, in your routing process.
crypto dynamic-map outside_dyn_map 10 set security-association lifetime seconds 288000
--> configure the lifetime for Phase 2 (IPSec) to 288000 seconds (80 hours)
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
[toc:faq]Introduction:This document describes details on how NAT-T
works.Background:ESP encrypts all critical information, encapsulating
the entire inner TCP/UDP datagram within an ESP header. ESP is an IP
protocol in the same sense that TCP and UDP are I...