ASA:dynamic map entry before regular map.
Hello Freinds,
ASA is configured correctly to support remote access VPN clients as well as for a lan to lan tunnel to another ASA. I spent half day trouble shooting why the L2L tunnel did not come up until I had a look at the Solution guide which has Dynamic map entry applied after L2L crypto map.
ASA2:
crypto map VPN 100 ipsec-isakmp dynamic DYNAMIC (this is for RA)
and
crypto map VPN 10 …args (for l2l , remote node is ASA1)
I could not figure out why L2L tunnel did not come up when I had dynamic entry applied before L2L entry and both were using different Transform Set.
When tunnel is initiated from ASA1 then should not it move to next VPN entry if the transform set did not match in the dynamic map?
-Ajay
Blogs and organic groups at http://www.ccie.net
























