是的,可以指示设备接受来自它已经拥有开放隧道的对等方的客户端 VPN 连接。
这是通过更新动态映射以包含具有已配置对等地址的新条目来完成的。
因此,使用此现有配置接受来自任何地址的动态连接:
crypto map vpnmap 10 match address peer_acl
crypto map vpnmap 10 set peer 192.0.2.15
crypto map vpnmap 10 set ikev1 transform-set ESP-AES-SHA1
crypto map vpnmap 65500 ipsec-isakmp dynamic OUTSIDE_DYN_MAP
crypto dynamic-map OUTSIDE_DYN_MAP 100 set ikev1 transform-set ESP-3DES-SHA
crypto dynamic-map OUTSIDE_DYN_MAP 100 set security-association lifetime seconds 86400
crypto dynamic-map OUTSIDE_DYN_MAP 100 set reverse-route
..可以编辑动态映射以允许来自对192.0.2.15
等方的客户端 VPN 连接:
crypto map vpnmap 10 match address peer_acl
crypto map vpnmap 10 set peer 192.0.2.15
crypto map vpnmap 10 set ikev1 transform-set ESP-AES-SHA1
crypto map vpnmap 65500 ipsec-isakmp dynamic OUTSIDE_DYN_MAP
crypto dynamic-map OUTSIDE_DYN_MAP 10 set ikev1 transform-set ESP-3DES-SHA
crypto dynamic-map OUTSIDE_DYN_MAP 10 set security-association lifetime seconds 86400
crypto dynamic-map OUTSIDE_DYN_MAP 10 set reverse-route
crypto dynamic-map OUTSIDE_DYN_MAP 10 set peer 192.0.2.15
crypto dynamic-map OUTSIDE_DYN_MAP 100 set ikev1 transform-set ESP-3DES-SHA
crypto dynamic-map OUTSIDE_DYN_MAP 100 set security-association lifetime seconds 86400
crypto dynamic-map OUTSIDE_DYN_MAP 100 set reverse-route
..和客户端 IPsec 连接现在将被允许,192.0.2.15
尽管有一个活动的 LAN 到 LAN 隧道。