pix multiple ipsec tunels dynamic ip address

Discussion in 'Cisco' started by no, Apr 1, 2005.

  1. no

    no Guest

    If I want to have several simultanious ipsec tunnels with remote non cisco
    routers with dynamic IP addresses, can I configure PIX using dynamic map?
    How PIX will know wich subnet is behind wich peer?

    no, Apr 1, 2005
  2. no

    mcaissie Guest

    Yes you can.

    In a dynamic map you can still create an entry per tunnel an specify
    such as the match address

    no] crypto dynamic-map dynamic-map-name dynamic-seq-num match address

    To only problem is that only the remote site will be able to initiate the
    tunnel. But depending on your needs it may not be a problem.
    mcaissie, Apr 1, 2005
  3. no

    no Guest

    I hope it will work, next week I will get additional equipement and try
    with several tunnels. But I still do not understand how PIX will know wich
    IP subnet is behind which peer. Peers are routers with wan interface to
    provider (dynamic addresses), and eth to network with devices that need
    secure communication to central site

    no, Apr 2, 2005
