Re: 12.1.X / IPSec

From: Philippe Stassin (stassinp@xxxxxxxxx)
Date: Tue Dec 26 2000 - 20:28:53 GMT-3


   
Hi,

All IOS's have bugs as far as IPSec is concerned !!!

... but in simple scenarios 12.0-7 or 12.0-9 will be OK.

Mixing static and dynamic crypto map will work but you will get into
troubles !

In real life, do upgrade your router to the very late release but for the
CCIE lab you will deal with 12.0.x

With a 2600 plateform, don't expect running more than ... 3 IPSec tunnels !
(Regardless of the encrypt/decrypt rate). Consider rebooting your 2600
on each major config change.

Tip: in a lab environment, keep your lifetimes short (300 sec for isakamp
       and 360 sec for ipsec).

Good luck !

Philippe.

-----Original Message-----
From: Arthayuth.B@datacraft-asia.com <Arthayuth.B@datacraft-asia.com>
To: ccielab@groupstudy.com <ccielab@groupstudy.com>
Date: Tuesday, December 26, 2000 7:53 AM
Subject: 12.1.X

>Dear All,
>
>I try to setup lab for CCIE Lab. Who know which version of 12.1 for
>Enterprise/FW/IDS Plus IPSec 56 for 2600 is stable ?
>
>
>=======================================================
>Arthayuth Boonruengrod
>Network Consultant
>CIP, CCNA, CCDA
>Datacraft (Thailand) Ltd.
>*14th Floor, Lake Rajada Building, Ratchadaphisek Road, Khlong-Toey,
Bangkok
>10110
>* arthayuth.b@datacraft-asia.com http:\\www.datacraft-asia.com
>* (662)264-0400, 661-9368 Ext# 104 Fax: (662)264-0405, 661-9488 *
>(661)684-8548
>=======================================================
>



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 08:26:10 GMT-3