Easy IPSEC Access Lists

Hi,

I am trying to setup a VPN in a hub and spoke topology and currently have all the devices talking to the hub, without any major issues. I am now wanting to get all the spokes to be able to access each other, is there any way of doing this without having to put every destination in as a access list, eg. access-list 100 deny ip 192.168.121.0 0.0.0.255 any access-list 100 permit ip 192.168.121.0 0.0.0.255 any access-list 115 permit ip 192.168.121.0 0.0.0.255 195.111.111.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.2.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.7.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.117.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.118.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.119.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.120.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.122.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.123.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 172.16.1.0 0.0.0.255 access-list 115 permit ip 192.168.121.0 0.0.0.255 192.168.3.0

I can see this been a real nighmare everytime I add a device onto the VPN and the inital setup it also very very complicated when you multiply it by

10 or so devices.

Thanks

Reply to
machine
Loading thread data ...

You might want to check out the DMVPN feature.

Reply to
Merv

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.