name 10.0.15.0 LAN_SUBNET
name 192.168.15.0 REMOTE_SUBNET
access-list outside_cryptomap_20 permit ip LAN_SUBNET 255.255.255.0 REMOTE_SUBNET 255.255.255.0
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map outside_map 20 ipsec-isakmp
crypto map outside_map 20 match address outside_cryptomap_20
crypto map outside_map 20 set peer 200.199.199.205
crypto map outside_map 20 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
isakmp enable outside
isakmp key ******** address 200.199.199.205 netmask 255.255.255.255 no-xauth no-config-mode
isakmp identity address
isakmp nat-traversal 20
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
name 192.168.15.0 LAN_SUBNET
name 10.0.15.0 REMOTE_SUBNET
access-list outside_cryptomap_20 permit ip LAN_SUBNET 255.255.255.0 REMOTE_SUBNET 255.255.255.0
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map outside_map 20 ipsec-isakmp
crypto map outside_map 20 match address outside_cryptomap_20
crypto map outside_map 20 set peer 201.189.199.205
crypto map outside_map 20 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
isakmp enable outside
isakmp key ******** address 201.189.199.205 netmask 255.255.255.255 no-xauth no-config-mode
isakmp identity address
isakmp nat-traversal 20
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
name 10.0.15.0 LAN_SUBNET
name 192.168.15.0 REMOTE_SUBNET
access-list outside_1_cryptomap extended permit ip LAN_SUBNET 255.255.255.0 REMOTE_SUBNET 255.255.255.0
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto map vpn_map 1 match address outside_1_cryptomap
crypto map vpn_map 1 set peer 200.199.199.205
crypto map vpn_map 1 set transform-set ESP-3DES-MD5
crypto map vpn_map interface outside
crypto isakmp identity address
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
tunnel-group 200.199.199.205 type ipsec-l2l
tunnel-group 200.199.199.205 ipsec-attributes
pre-shared-key *
name 192.168.15.0 LAN_SUBNET
name 10.0.15.0 REMOTE_SUBNET
access-list outside_1_cryptomap extended permit ip LAN_SUBNET 255.255.255.0 REMOTE_SUBNET 255.255.255.0
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto map vpn_map 1 match address outside_1_cryptomap
crypto map vpn_map 1 set peer 201.189.199.205
crypto map vpn_map 1 set transform-set ESP-3DES-MD5
crypto map vpn_map interface outside
crypto isakmp identity address
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
tunnel-group 201.189.199.205 type ipsec-l2l
tunnel-group 201.189.199.205 ipsec-attributes
pre-shared-key *
no crypto map outside_map 20 set peer 201.189.199.205
crypto map outside_map 20 set peer 201.189.199.204
no isakmp key ******** address 201.189.199.205 netmask 255.255.255.255 no-xauth no-config-mode
isakmp key presharedkey address 201.189.199.204 netmask 255.255.255.255 no-xauth no-config-mode
no crypto map vpn_map 1 set peer 201.189.199.205
crypto map vpn_map 1 set peer 201.189.199.204
clear configure tunnel-group 201.189.199.205
tunnel-group 201.189.199.204 type ipsec-l2l
tunnel-group 201.189.199.204 ipsec-attributes
pre-shared-key presharedkey
isakmp enable outside
isakmp key ******** address 201.189.199.205 netmask 255.255.255.255 no-xauth no-config-mode
isakmp identity address
isakmp nat-traversal 20
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
crypto isakmp identity address
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
crypto map outside_map 20 set pfs group1
Total : 1
Embryonic : 0
dst src state pending created
173.14.215.29 WAN QM_IDLE 0 1
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1
1 IKE Peer: 201.189.199.205
Type : L2L Role : responder
Rekey : no State : MM_ACTIVE
Have a question about something in this article? You can receive help directly from the article author. Sign up for a free trial to get started.
Comments (0)