IPSec Site to MultiSite Part 2

  Рет қаралды 2,487

CCNP Seth

CCNP Seth

Күн бұрын

Пікірлер: 11
@abdullahasim8010
@abdullahasim8010 Жыл бұрын
good job
@karimsalah6991
@karimsalah6991 5 жыл бұрын
Great work .. thank you... what is maximum branches can i configure on R1 ?
@ccnpseth4563
@ccnpseth4563 5 жыл бұрын
When it comes to IPSEC tunnels, it all depends on the platform you are using. The more tunnels, the more resources that are going to be consumed. Therefore, there are line cards that can be used to offload the processing power from the Route processor to hardware.
@karimsalah6991
@karimsalah6991 5 жыл бұрын
@@ccnpseth4563 Suppose that the headquarters of the company has a very strong router with a high-speed Internet socket .... Do these specifications allow me to create 6 encrypted tunnels associated with the company's branches. ?? With this technique I can create many branches online instead of using v35 connection
@mitpatel4268
@mitpatel4268 5 жыл бұрын
Hi Seth, Thank you for publishing such wonderful videos. I have a question, however. If we want to build 3 tunnels - 1 HQ and 3 Remote offices, can we use a single ISAKMP policy and a single transform set, given that the peers and keys are appropriately and uniquely configured? Sorry if this was a silly one and I was missing out something basic but, my ultimate query is - can we reuse one ISAKMP policy for multiple tunnels? And how about IPSEC policy reuse?
@ccnpseth4563
@ccnpseth4563 5 жыл бұрын
Yes, keep the transform set the same for all peers and define interesting traffic for all peers in the ACL
@mitpatel4268
@mitpatel4268 5 жыл бұрын
@@ccnpseth4563 thanks for prompt response! So it's all about segregating using the crypto ACLs and of course the policies should match? We can make this work using a single phase 1 and 2 policy sets...? Provided the proposals are matching and accepted and PSKs match as well...
@ccnpseth4563
@ccnpseth4563 5 жыл бұрын
@@mitpatel4268 yes
@mitpatel4268
@mitpatel4268 5 жыл бұрын
@@ccnpseth4563 Thank you
@anandpathak4311
@anandpathak4311 8 жыл бұрын
so as per video we dont need any configuration on the other end routers . R4 and R3 in this case.
@ccnpseth4563
@ccnpseth4563 8 жыл бұрын
you do, the two isakmp policies and transform sets matched the configs for r3 and r4. for ipsec and crypto maps, both sides need to have the same configs except the IP addresses and ACLs, which need to flipped. that's why I didn't show r3 & r4 configs.
How many people are in the changing room? #devil #lilith #funny #shorts
00:39
Леон киллер и Оля Полякова 😹
00:42
Канал Смеха
Рет қаралды 4,5 МЛН
“Don’t stop the chances.”
00:44
ISSEI / いっせい
Рет қаралды 53 МЛН
If you have multi Site vpn or dplc link?
6:20
Rean IT Khmer រៀនអាយធីខ្មែរ
Рет қаралды 1,2 М.
Massive News! Free Network Simulation Tool for Everyone! (Cisco CML)
16:52
Multiple Site to Site IPSec VPN Cisco Router
26:32
CMV - Network Solutions
Рет қаралды 7 М.
Cisco CME Lab from Start to Finish
37:09
CCNP Seth
Рет қаралды 21 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,4 МЛН
How many people are in the changing room? #devil #lilith #funny #shorts
00:39