Cisco Systems Is the crypto map order important ? Or is that between ezvpn and l2tp/ipsec ?

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Is the crypto map order important ? Or is that between ezvpn and l2tp/ipsec ? dt1649651@yahoo.com 04-22-08
Posted by dt1649651@yahoo.com on April 22, 2008, 3:28 pm
Please log in for more thread options
My router is configured to work as ezvpn server, site-to-site and l2tp/
ipsec gateway. This l2tp/ipsec is for mobile devices ( Windows mobile
2003 premium or 2005 ) which support by default l2tp/ipsec but not
cisco vpn client.

I have no problem with configuration of site-to-site with ezvpn or of
site-to-site with l2tp/ipsec gateway. But when I let all three to work
together, it seems there is some conflict between the l2tp/ipsec and
ezvpn.

If the crypto map command for ezvpn has smaller order number then
ezvpn clients work, and l2tp/ipsec client cannot make the connection.

If the crypto map command for l2tp has smaller order number then l2tp/
ipsec clients work, and ezvpn clients can make the connection but go
nowhere.

site-to-site ipsec is still happy no matter what crypto map numbers of
l2tp or ezvpn are.

Is that because both l2tp/ipsec and ezvpn in this configuration have
dynamic peers so they fight each other ?


Thanks,

DT

Similar ThreadsPosted
Is the crypto map order important ? Or is that between ezvpn and l2tp/ipsec ? April 22, 2008, 3:28 pm
Important about Cisco Certifications November 6, 2007, 10:02 am
Important about Cisco Certifications November 6, 2007, 10:02 am
Important about Cisco Certifications November 7, 2007, 12:41 am
Cisco Memory Monitoring Largest(b) the most important? October 12, 2006, 11:22 am
Is ATM still an important part of the CCIE (SP) lab? Equipments needed for ATM scenarios? February 11, 2006, 11:03 pm
Re: Is ATM still an important part of the CCIE (SP) lab? Equipments needed for ATM scenarios? February 12, 2006, 4:15 pm
Order of NAT, ACL, VPN etc in IOS September 25, 2005, 4:07 am
PIX - NAT order. March 15, 2006, 8:43 am
Order of authentication. July 28, 2005, 4:13 pm
order of the actions taken by a router. March 3, 2006, 1:55 pm
Dynamic / Static NAT order of preference January 30, 2006, 4:51 pm
ezvpn: ip pool necessary? June 27, 2006, 1:54 pm
Cisco 877 and EZVPN !?!?! July 6, 2007, 10:45 am
ezvpn with ipsec over tcp May 5, 2008, 12:06 am