Surprised with connection not matching acl

Apr 28, 2005 0 Replies

Hello all



I have a tunnel set-up on my Cisco 1760, with static IP endpoints and access list applied in the crypto map. I dont know the remote VPN endpoint equipment.



The acl states "permit ip 192.168.202.0 0.0.0.255 192.168.28.0 0.0.0.255" but I saw with the "sh crypto ipsec sa" that the remote network



192.168.202.0 is accessing not only the allowed network but also a different one on my site.

Is there a way to control that ?



Thanks



Jaime


Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required