card crypto access lists / problem if more than one entry?

Access list for IPSec enabled traffic.

I've been recently setting up a VPN between two sites and I came across the following problem:

I wanted to install a VPN that only 2 posts from site A to site B, a class C network

So I created a list of access as follows:

access-list 101 permit IP 192.168.0.1 host 192.168.1.0 0.0.0.255

access-list 101 permit IP 192.168.0.2 host 192.168.1.0 0.0.0.255

When I applied the access list above to map (match address 101) encryption, I quickly realized that only the first host (192.168.0.1) was successfully encrypted beeing while the other could not. I've been geeting on ipsec debugging errors saying that traffic to 192.168.0.2 denyed by the access list.

When I changed the access list above with the following

access-list 101 permit IP 192.168.0.1 0.0.0.255 192.168.1.0 0.0.0.255

two items of work could successfully encrypted through IPSec tunnel.

To look further into it, I realized that only the first entry of the IPsec access list has been really tested for the corresponding traffic!

Is this a normal behavior or a known Bug? No work around for this problem?

Kind regards.

If you have ipsec-manual crypto map in crypto ACL, you can specify that an ACE. Check 12.2 docs:

Access lists for labelled as ipsec-manual crypto map entries are limited to a single permit entry and the following entries are ignored. In other words, the security associations established by this particular entry card crypto are only for a single data stream. To be able to support several manually created security for different types of traffic associations, define multiple crypto access lists and then apply each a separate entrance card crypto ipsec-manual. Each access list should include a statement to define which traffic to protect.

Tags: Cisco Security

Similar Questions

  • Receive messages because I access my email from more than one computer, I have to refresh my browser. I have only one computer. How can I get rid of the message?

    Why I get the message that I have to refresh my browser as it says am I access my email from more than one computer.  I'm not.  When I was over at a friends yesterday I saw my email from his computer and the message did not come.

    It sounds as if your browser security settings prevent the site to save a cookie is used to identify computers that were previously used to log on to the account.

    It would have helped if you had identified what browser including the version that you use.

    If you use Internet Explorer 7 or 8, see http://windows.microsoft.com/en-US/windows-vista/Block-or-allow-cookies

    If you use Internet Explorer 6, see http://support.microsoft.com/kb/283185/EN-US

    If you are using another browser, please log in.

  • My music player has more than one entry for a song and when I buy a song or download to the reader I'm going to finish with three entrances.

    Original title: getting copied songs and resumes somehow

    Because of the settings or something my music player has more than one entry for a song... so when I buy a song or download from my phone to the player so I'll finish with three entries... on an album of 10 songs I get 30.  3 of each song... even with pictures... is it a setting or is there a way to automatically set the drive remove the redundant songs and photos?

    Hello

    1 Windows operating system you are using?

    2 are you facing issue with Windows media player?

    If you are facing the issue with Windows Media Player, you can try the following steps and check if it helps:

    Method 1:

    You can delete the Windows Media Player database and check if the problem persists.

    Step 1:

    a. exit Windows Media Player.

    b. click Start, click Run, type %userprofile%\Local Settings\Application Data\Microsoft\Media Player in start searchand then click OK.

    c. Select all files in the folder, and then click delete on the file menu.

    Note: you don't have to remove the folders that are in this folder.

    d. restart Windows Media Player.

    Note: Windows Media Player automatically rebuilds the database.

    If this does not resolve the problem, disable the Windows Media Player database cache files. To do this, follow these steps:

    Step 2:

    a. exit Windows Media Player.

    b. click Start, click Run, type %LOCALAPPDATA%\Microsoftand then click OK.

    c. Select the folder Media Playerand then click delete on the file menu.

    d. restart Windows Media Player.

    Note: Windows Media Player automatically rebuilds the database.

    For more information, see the article:

    Method 2:

    If you are using Windows 7, you can also try to launch Windows Media Player convenience stores on the library and check if it helps.
    Convenience store open in Windows Media Player library

    Method 3: How to prevent duplicateor entered invalid frombeing added to mylibrary during playback of music files?

    When you move digital media files on your computer, the file name and file path information remain unchanged in your library. Then when you select a file to play to its new location, a new entry is created in your library if you select the option automatically added to your library when played. As a result, your library can quickly contain a large number of entries, duplicate or invalid.

    To prevent it be automatically added to your library of music files
    a. in Windows Media Player, on the Tools menu, click on Options.
    b. on the Player tab, clear music to add to the library when played check box.
    Now, when you play music on your computer or the Internet, the file will not be added automatically to your library.

  • Can I access my programs from more than one computer? If so, how?

    I want to know if I can access my CC programs from more than one computer? If so, how? This may seem like a silly question, but the cloud is still confusing to me.

    Cloud license allows 2 activations http://www.adobe.com/legal/licenses-terms.html

    -Install on a 2nd computer http://forums.adobe.com/thread/1452292?tstart=0

    -Windows or Mac has no importance... 2 on the same operating system or 1 on each

    -Two activations may NOT be used at the same time (noted in the link above of the license)

  • Game-OSCustomizationSpec - GuiRunOnce adding more than one entry.

    So I try to figure out how I can change all of my current scripts by adding some registry changes more via powershell for guirunonce entry.  I find myself with an entry that contains all my changes to reg instead of multiple entries, as shown in the screenshots.  This is what I am running.

    Game-OSCustomizationSpec-spec TEST - GuiRunOnce "reg delete"HKLM\SOFTWARE\Network Associates\ePolicy Orchestrator\Agent"/v AgentGUID/f, reg delete"HKLM\SOFTWARE\Network Associates\ePolicy Orchestrator\Agent"/v MacAddress, f.

    The MultiLine.jpg shows how the spec looked before running the script.  The Oneline.jpg shows what it looks like after running the cmdlet.  Any ideas?

    Zsoldier wrote:

    Game-OSCustomizationSpec-spec TEST - GuiRunOnce "reg delete"HKLM\SOFTWARE\Network Associates\ePolicy Orchestrator\Agent"/v AgentGUID/f, reg delete"HKLM\SOFTWARE\Network Associates\ePolicy Orchestrator\Agent"/v MacAddress, f.

    Try each line in its own set of quotes, separated by a comma.

    -GuiRunOnce "reg delete 'HKLM\SOFTWARE\Network Associates\ePolicy Orchestrator\Agent' /v AgentGUID /f", "reg delete 'HKLM\SOFTWARE\Network Associates\ePolicy Orchestrator\Agent' /v MacAddress /f"
    

    =====

    Carter Shanklin

    Read the PowerCLI Blog
    [Follow me on Twitter |] http://twitter.com/cshanklin]

  • Hotmail problem - "Please refresh your browser window. When you access your Windows Live Hotmail account from more than one computer"

    How can I solve the problem with this message: "Please refresh your browser window. "We ask to reconnect when you access your Windows Live Hotmail account from more than one computer, help keep your account secure and private.

    Thank you for visiting the Microsoft answers community site!

    The question you have posted is related to Windows Live Hotmail and would be better suited in the Windows Live Solution Center.

    Please visit the link below to find a community that will support what ask you

    http://windowslivehelp.com/forums.aspx?ProductID=1

    Cody C
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • How to list all the vm with more than one network card?

    Hello

    Is it possible to only list all my s vm in my environment with more than one network card?

    I tried using the Get-NetowrkAdapter cmdlet, but could not get the desired results.

    Get - VM | Get-NetworkAdapter | Select-Object Name. ConvertTo-HTML-head $a - body "Virtual Machines < H2 > < / H2 > ' | Out-file D:\vms.htm

    Thank you

    Hello, AGFlora-

    Of course, you can do this with the standard as cmdlets:

    ## using standard cmdletsGet-VM | Select Name, @{n="NumNICs"; e={(Get-NetworkAdapter -VM $_ | Measure-Object).Count}} | ?{$_.NumNICs -gt 1}
    

    Or, if you want to get the results a little (or a lot) more quickly, you can use the cmdlet Get-view as:

    ## fast-like, using Get-ViewGet-View -ViewType VirtualMachine -Property Name,Config.Hardware.Device | Select Name,@{n="NumNICs"; e={($_.Config.Hardware.Device | ?{$_ -is [VMware.Vim.VirtualEthernetCard]} | Measure-Object).Count}} | ?{$_.NumNICs -gt 1}
    

    Those are both by selecting the names of virtual machines and their number of network cards.  Then you can direct this output to Export-Csv, ConvertTo-HTML, what you like.  What to do for you?

  • Access Windows Live Hotmail from more than one computer

    Original title: "brawser.
    Fazer by Nao sei o. I can not open messages, only the entro minhas no our mas nao posso mexer mail only mails. Appears a mensagem, fazer o abaixo?
    Please, refresh your browser window. When you access your Windows Live Hotmail account from more than one computer, please reconnect help keep your account secure and private.

    The forum language is English.  Google Translate says it's:

    "I don't know what to do. Can not open my mail, simply enter the email but I can don't mess with mail. The message below, what to do? ».

    This seems to be a problem of access to Hotmail.  So, you should ask your question (in English) in the center of Windows LiveHotmail Portalsolutions.

    Brian Tillman [MVP-Outlook]
    --------------------------------
    https://MVP.support.Microsoft.com/profile/Brian.Tillman
    If a response may help, please vote it as useful. If a response to the problem, please mark it as an answer.

  • How can I put more than one detail in a select list/menu?

    Hi guys! If someone could help me with this problem, I have would be great!

    I'm putting more than one dynamic field on a line in a list/menu select for example... HomeTeam, AwayTeam, Kick Off Date v (mainValue)

    The code of the selection list is below.

    < select name = 'test' id = 'test' >

    <? PHP

    {}

    ? >

    < option value = "<?" PHP echo $row_fixtures ["HomeTeam"]? ' > ' > <? PHP echo $row_fixtures ["HomeTeam"]? > < / option >

    <? PHP

    } While ($row_fixtures = mysql_fetch_assoc ($fixtures));

    $rows = mysql_num_rows ($fixtures);

    If ($rows > 0) {}

    mysql_data_seek ($fixtures, 0);

    $row_fixtures = mysql_fetch_assoc ($fixtures);

    }

    ? >

    < / select >

    You have the values in the same record?

    Please present the structure of the database.

    normally the select option would look like

  • CMDGW_CAT:3441: ERROR: can not have more than 3 entries in the LIST RACCESSPOINT

    Hello
    I have Tuxedo 8.1 in HP - UX.


    In the section of my dmconfig that I have:

    ....
    .....

    SERVICEF LDOM = DOMLOCAL RDOM = WTC1, WTC2, WTC4 WTC3
    .....
    .....

    I have this error when I tried to compile with dmloadcf y dmconfig:

    Invalid value
    CMDGW_CAT:3441: ERROR: can not have more than 3 entries in the LIST RACCESSPOINT
    CMDGW_CAT:1546: ERROR: dmloadcf: above the errors found during the syntax check

    increase the value of the parameter RDOM plus 3?
    How?

    Thank you...

    Hello

    Syntax:

    Service LDOM = local_domain RDOM = dom1, dom2, dom3

    sets the remote domains of failover for this particular import. It is not intended to provide access to a service in several areas. What you want, it's basically what you were doing, i.e.,.

    Service LDOM = local_domain, RDOM = dom1, dom2
    Service LDOM = local_domain, RDOM = dom2, dom3
    Service LDOM = local_domain, RDOM = dom3, dom4
    Service LDOM = local_domain, RDOM = dom4, dom1

    It would provide balance between the 4 areas and always provide areas of failover, although assigned to the ON_STARTUP linking strategies, then the following is sufficient:

    Service LDOM = local_domain, RDOM = dom1
    Service LDOM = local_domain, RDOM = dom2
    Service LDOM = local_domain, RDOM = dom3
    Service LDOM = local_domain, RDOM = dom4

    As only active areas will be used and those inactive is ignored.

    Kind regards
    Todd little
    Chief Architect of Oracle Tuxedo

  • How to select and move more than one bookmark at a time? Shift + click selects multiple items that are next to each other in a list, because the element

    How to select and move more than one bookmark at a time?
    Shift + click selects multiple items that are next to each other in a list, because the items open in firefox before that happens.

    Glad it worked for you. Thanks for posting back.

  • Is there a way to allow more than one person accessing and editing a file

    Original title: records of public folders

    Hi, when there is a file on a public folder cannot be access by one person at a time or you get the message 'open read-only '. Is there a way to allow more than one person accessing and editing a file at the same time on a shared drive?

    It's true, but there are a few special cases.  For example, spreadsheet Microsoft Excel is adjustable mode "shared" so that more than one person can make changes at the same time.  If two people edit the same section of the file, they get a prompt asking you which changes are preserved.

    That said-I was never able to use it effectively.

  • more than one user connects to pc (windows7). How can I block access to my media

    more than one user connects to pc (windows7). How can I block access to my media

    Original title: media sharing options?

    Hi Gabe,

    I appreciate the efforts that you put to publish the query on this forum.

    It would be better if you can provide additional information related to this query:

    Who are the media that you are trying to secure on the computer? Is it related to any multimedia files or folders?

    If you try to get the files or folders, you can use the Windows 7 encryption method to do:

    http://Windows.Microsoft.com/en-in/Windows7/encrypt-or-decrypt-a-folder-or-file

    Please get back to us with more information to help you better.

  • I have to remove the duplicate files, but having problems by selecting more than one file in the player at the time.

    I have to remove the duplicate files, but having problems by selecting more than one file in the player at the time. How can I select multiple files at the same time so I can just delete them. I used to be able to do this in previous versions of Media Player, but this function seems now blocked or unavailable. The problem is this: through previous use of media player, it plays all my multimedia files several times whenever a device support has been added. He would try to save the files on my main drive, but since there is not enough room this would save the files somewhere else. This happened several times, I suppose, because when I upgraded my computer and a media scan was conducted he found duplicates of all my media various times of at least 6-8. I've consolidated since my plates on 3-disc multi to, but have now records duplicated hundreds and thousands of duplicate media files. Previous versions of Media Player would allow me to select all files and then delete them both of the reader, but also from my hard drive. So now I'm stuck with more than 300 GB of duplicate media I have to search line by line through all my hard drives to find each duplicate both, unless I can get media player to do what it can. Any help in this area would be appreciated.

    Hello

    1. did you of recent changes on the computer?

    2. is Windows media player files in double creation during playback of music files?

    To delete duplicate entries, click on another feature tab in the drive (for example the current playback), and then click library.

    If this does not remove duplicates from your library, you can use the Add to library dialog box to search computer to analyze a file on your computer the duplicate entries not valid-pointing. The player will remove invalid entries in your library that point to files that no longer exist in the folder.

    Complete the steps above for files that are stored in the hard disks.

    Method 1: Use the add to Library dialog box search for computers

    (a) start Windows Media Player.

    (b) press F3 on your keyboard to open Add to the library of the find computers dialog box.

    (c) click the Browse button to locate the folder on your computer so that your library contains invalid entries. Specify the location of the folder in the box look in.

    If you are not sure what duplicate in your library entry is not valid, you can add a path column to display in your library. Specify the folder on your computer that corresponds to the path not valid file displayed in your library.

    (d) click on the Search button.

    The player will search for digital media files and playlists in the folder that you specify and remove invalid entries in your library that point to files that no longer exist in the folder. If not valid in double entries point to other folders on your computer, repeat this procedure, specify a different folder every time.

    If only a small number of duplicate entries exist, you can delete those invalid manually by right-clicking on the invalid entry, and then clicking Delete .

    For large double-number of entries in your library (or if all your library is duplicated), it might be better to create a new library and delete the files.

    Method 2:

    After you remove the duplicate entries, run the troubleshooting of Windows Media Library settings to solve this problem.

    Open the troubleshooter in Windows Media Library

    http://Windows.Microsoft.com/en-us/Windows7/open-the-Windows-Media-Player-library-Troubleshooter

    Let us know the results.

    I hope this helps.

  • More than one variable target card only transform?

    Hello

    I was wondering if more than one target variable is allowed in a single transformation plan? If so, how?

    Thank you

    Hello

    It is not possible.

    You can have several sources, but only a single target.

    You must consider revising your definition of the variable target to include multiple items to use.

    Antonis

Maybe you are looking for