I have Microsoft clients using Cisco's VPN Client 4.6.x connecting to a Cisco 3005 Concentrator to provide remote access to my LAN. From the IPSec architecture documents I understand that should be able to configure a responder (i.e., the Concentrator) to support multiple IKE Proposals and SAs and define a selection hierarchy; however, it *appears* the concentrator only provides a method to accept *one* SA via "Configuration | User Management | Groups | Modify |IPSec".
Is there a way of configuring the concentrator to accept a range of SAs? As far as I can tell the only way to configure the Concentrator to accept multiple SAs is to define multiple groups and let the user on the client choose the group to use. That seems broken, so I'm thinking I don't know what I'm doing