From: cannonr (cannonr@xxxxxxxxx)
Date: Sat Jul 27 2002 - 11:05:15 GMT-3
FYI, at Networkers, they said that in new versions of code, they are going
to remove the requirement to apply the crypto map statement to the both the
physical and logical interfaces. You will need to apply the crypto map only
to the GRE inteface in the future.
----- Original Message -----
From: "Anthony Pace" <anthonypace@fastmail.fm>
To: <ccielab@groupstudy.com>
Sent: Wednesday, July 24, 2002 7:32 PM
Subject: IPSEC and GRE
> To encrypt a GRE tunnel is it best to apply the crypto map to the GRE
> tunnel interface or the real interface(s) the traffic will ultimatly
> traverse. If the answer is both, then do I set up the access-list to
> encrypt all IP or just GRE traffic.
>
> I would think that if you applied the map to the real interface, and
> the ACL matched GRE then it would work.
>
> I would think that if you appplied the map to the GRE, and the ACL
> matched all IP then it would also work.
>
> The examples I have seen put it on both. What is the difference and
> does it matter?
>
> Anthony Pace
> --
> Anthony Pace
> anthonypace@fastmail.fm
>
> --
> http://fastmail.fm - Email service worth paying for. Try it for free.
This archive was generated by hypermail 2.1.4 : Sat Sep 07 2002 - 19:36:46 GMT-3