RE: IPSEC over DDR

From: Richard Dumoulin (Richard.Dumoulin@vanco.fr)
Date: Sun Jun 19 2005 - 19:05:18 GMT-3


This is an interesting question. I have a dialer-list referencing an ACL 150
and see what traffic has heat it:

router#sh access-li 150
Extended IP access list 150
    10 deny udp any eq isakmp any eq isakmp (181 matches)
    20 permit esp any any (74 matches)
    50 permit ip 10.30.135.192 0.0.0.63 any (2981 matches)
    60 permit ip 192.18.135.0 0.0.0.255 any (409 matches)

I think it is the clear text traffic that triggers/maintains the isdn call
but always test the behavior before putting the router in production,

-- Richard

-----Original Message-----
From: EdmondsSG@aol.com [mailto:EdmondsSG@aol.com]
Sent: Sunday, June 19, 2005 10:46 PM
To: ccielab@groupstudy.com
Subject: IPSEC over DDR

Group,
 
just a quick question,
 
when configuring IPSEC over say ISDN, what should be classed as
interesting
traffic? - the actual IP's or the IPSEC tunnel?
 
?
 
Segster



This archive was generated by hypermail 2.1.4 : Wed Jul 06 2005 - 14:43:41 GMT-3