Asymetric IPSec transform sets - Inbound vs Outbound

From: Sadiq Yakasai <sadiqtanko_at_gmail.com>
Date: Thu, 21 May 2009 14:42:07 +0100

Guys,

So, I think i'm spending too much time in the books and theories, but I
gather that its possible to configure different transform sets for the Phase
2 SA's ( inbound vs outbound)...with repect to the tunnel endpoints.

So is this really possible? First try didnt go successful, but looking at it
again, I have a few doubts that might need clearing up.

So in total, on each peer, how many transform sets do I need (if this
convolution is even possible to begin with)? 2 on each side (while swapping
the ordering of how they are bound to the crypto map?) thereby making them
asymetric sort of?

Thanks in advance as usual,
Sadiq

-- 
CCIE #19963
Blogs and organic groups at http://www.ccie.net
Received on Thu May 21 2009 - 14:42:07 ART

This archive was generated by hypermail 2.2.0 : Mon Jun 01 2009 - 07:04:43 ART