Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Route based IPSEC VPN Config between SSG-550M and Cisco ASA

$
0
0

Hi Ishaik,

 

AFAIK, there is no 'no proxy-id' - definitiely not on the Cisco boxes. If they had configured an accept-all proxy-id, then your VPN would have some up whith 0.0.0.0/0 as proxy ID.

If you want to test, just try injecting traffic for a new remote subnet (say 10.0.10.0/24) into the VPN by setting a route for this subnet pointing to tunnel and adding the permit policies as required.

 

If it comes to configuring new proxy-IDs, yes - you are right. Every proxy-ID pair will bring up its own SA.


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>