RE: Question on Lab 15 - VPN

From: Baiao, Nuno (Nuno.Baiao@xxxxxxxxxx)
Date: Wed Dec 05 2001 - 09:58:49 GMT-3


   
James,

You are right the solutions they give in the ccbootcamp is kind of wrong
because the access-list should be
access-list 100 permit gre host 150.100.50.42 host 160.200.77.122 because
those are the termination points of the tunnel you created and remember that
the question is to encrypt the tunnel.
Hope this helps.

Best compliments,

Nuno Baico
> Network Engineer Consultant
> KPMG Consulting
> KPMG Cisco Service Provider
> 6 The Square, Stockley Park, Uxbridge UB11 1JR United Kingdom
mobile: +44 7950 917 478
fax: +44 20 7694 3410
email: nuno.baiao@kpmg.co.uk

-----Original Message-----
From: Lopez, James [mailto:james.lopez@atosorigin.com]
Sent: Wednesday, December 05, 2001 12:23 AM
To: 'ccielab@groupstudy.com'
Subject: Question on Lab 15 - VPN

Hi Gang,

I'm missing something on encrypted VPN and I just can't seem to understand
why the access-list on the crypto map is using the Internet IP addresses
instead of the LAN addresses.

(i.e. on lab 15 - access-list 100 permit ip host 150.100.50.42 host
160.200.77.122)

Since the access-list is used to identify which traffic is encrypted, why
isn't it something like:

access-list 101 permit ip 10.0.0.0 0.255.255.255 10.5.8.0 0.0.0.255 on R8?

My current configuration is exactly like the answer sheet and I have
searched the archives and CCO and just can't seem to see the light.

> TIA,
> JL
                Email Disclaimer

The information in this email is confidential and may be legally privileged.
It is intended solely for the addressee. Access to this email by anyone else
is unauthorised.
If you are not the intended recipient, any disclosure, copying, distribution
or any action taken or omitted to be taken in reliance on it, is prohibited
and may be unlawful. When addressed to our clients any opinions or advice
contained in this email are subject to the terms and conditions expressed in
the governing KPMG client engagement letter.



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:32:39 GMT-3