site-to-site and easy vpn server on same interface

Is it possible to configure site-to-site and easy vpn server on the same interface ?

I get stuck at this point: when I apply the ezvpn paramters "client authentication list list_name", "client configuration address respond" and "isakmp authorization list list_name" to the crypto map *set*, then that screws up the site-to-site ipsec because the site-to-site crypto map is under that same crypto map set.

If I apply those mentioned parameters to the ezvpn *dynamic crypto map* then the site-to-site works but the ezvpn fails.

Below is the config that I apply the ezvpn to the dynamic crypto map instead of the crypto map set:

crypto dynamic-map ezvpn_remote_dynmap 10

Reply to
Loading thread data ...

take a look at

DMVPN and Easy VPN Server with ISAKMP Profiles Configuration Example

formatting link

Reply to

I am lucky. After comparing the ASA config and the IOS config and looking at some ios config, I found out that I can bind the specific dynamic crypto map ( not the whole set ) to a given isakmp profile. It works now.


Reply to

Merv, thanks a lot. Hmm, I spent three hours on Cisco site and found only examples that bind those params into the cypto map set instead of using the isakmp profiles. Your URL shows me what I was looking for. That shows I need to improve my using of correct key words when searching :)



Reply to
dt1649651 Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.